-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 20 Mar 2025 13:56:44 +0100 Source: mercurial Binary: mercurial mercurial-dbgsym Architecture: mips64el Version: 6.3.2-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Julien Cristau Description: mercurial - easy-to-use, scalable distributed version control system Closes: 1100899 Changes: mercurial (6.3.2-1+deb12u1) bookworm-security; urgency=high . * CVE-2025-2361: reflected XSS in hgweb (closes: #1100899) * patchbomb: don't test ambiguous address (fixes FTBFS after python's fix for CVE-2023-27043). Checksums-Sha1: ee8379768cab3ad424c26a236a7bc256a50c763c 1703152 mercurial-dbgsym_6.3.2-1+deb12u1_mips64el.deb 787d7c751a6588de1d47094f3f941e59ca38221e 7299 mercurial_6.3.2-1+deb12u1_mips64el-buildd.buildinfo 64b2e4d47a991a98206e2b7fed852aac05b332a8 326548 mercurial_6.3.2-1+deb12u1_mips64el.deb Checksums-Sha256: 79a1346b41c46e5c633adc73311aae5435f7d128155c0b4d3bde524bcafccb89 1703152 mercurial-dbgsym_6.3.2-1+deb12u1_mips64el.deb 0e09b364527364c1cea61b7799cc14f500c9e3e6be6ebac1d57a234865a5ff61 7299 mercurial_6.3.2-1+deb12u1_mips64el-buildd.buildinfo fc914267296532f6aa6d7672361bed6de07707ebaffc7169dbcc7f46e2822101 326548 mercurial_6.3.2-1+deb12u1_mips64el.deb Files: e57fd9a6387847e8516f7809553028ee 1703152 debug optional mercurial-dbgsym_6.3.2-1+deb12u1_mips64el.deb 7201ff42ac5b0c7a87a3cbdceff28122 7299 vcs optional mercurial_6.3.2-1+deb12u1_mips64el-buildd.buildinfo 524361407f147e661365fb3f9923c0ed 326548 vcs optional mercurial_6.3.2-1+deb12u1_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYLhEzFkGpb3yYRVHmlVdU6AM9BUFAmfcbHYACgkQmlVdU6AM 9BW+ug//T29Rh3Br5YuKd1kO1aWwi2gqCvBeRyM+A6B60ffzUebYDnuWczBhvQ90 BLbg+nnkCL9zSGBTmPZdAm3KN5+pRanX/c6qAJK6m1TaZSwkBKo4e4Boplu+/Tjy qdqUFXRaLGtPuVldYwa9JGHBPgt4MlLbNYmuQmqZS5C3r/WfbXgvSEZSBvk/wa2Q T8i64BS4wHcOTcy6m+xbrzQ5u7wUa0hB1q0zzAKbrZ1e8e3necfFbsr9I9aTTdkD ggZ0EuRvcd2I51yY+9+2zcE9wHv4XQlY9qg++4Vj59eEr7je7r0ZeoiquJxVscKQ kKq8jjkiZ7b5dYhaprdqiNzmg1gP0XccTsQl6jsjA9pe438wAMt4ltrpVwixVBxS TIj6oiDojJ6I5wT9DKUdpU2mY+oAIG7MZREeVucYd8MWV9wiXPRNrP17665LTLQu Xxwzv7WklnFmw1uZ7fthjUEVU8HlmdH3d6aaEzurJUN5rE/GyGk2iRkTLkJq6Q80 Y63lBURfn4qJCh/mD+N/2Fx/sDz5J4nsoI71ni06I+PtT8kaweMuOea6CbWpvYw2 tIXheLaK/HUQBf7TZyGqnFHRrK4maruS6Kf/BlPHm9TvtCgUTaz50Cf2/yQO67u3 PjpIslcNxmsSpeD+qm+T3chRjB/4VCQnbl040t1WrTYd+6Mz8VI= =8rFO -----END PGP SIGNATURE-----