The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9462
Reference (s):
- http://mercurial.selenic.com/wiki/WhatsNew
- http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
- DEBIAN:DSA-3257
- URL: http://www.debian.org/security/2015/dsa-3257
- GENTOO:GLSA-201612-19

