CVE-2008-4297
Publication date 27 September 2008
Last updated 24 July 2024
Ubuntu priority
Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an “hg pull” request.
Status
Package | Ubuntu Release | Status |
---|---|---|
mercurial | 8.04 LTS hardy | Ignored |
7.10 gutsy | Ignored | |
7.04 feisty | Ignored | |
6.06 LTS dapper | Ignored |