Related Vulnerabilities: CVE-2017-1000115  

Mercurial's symlink auditing was incomplete prior to 4.3, and could be abused to write to files outside the repository.

Severity High

Remote Yes

Type Arbitrary filesystem access

Description

Mercurial's symlink auditing was incomplete prior to 4.3, and could be abused to write to files outside the repository.

AVG-378 mercurial 4.2.2-1 4.2.3-1 Critical Fixed

12 Aug 2017 ASA-201708-7 AVG-378 mercurial Critical multiple issues

https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.3_.282017-08-10.29