========================================================================== Ubuntu Security Notice USN-4086-1 August 06, 2019 Mercurial vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.04 Summary: Mercurial could be made to overwrite files. Software Description: - mercurial: easy-to-use, scalable distributed version control system Details: It was discovered that Mercurial mishandled symlinks in subrepositories. An attacker could use this vulnerability to write arbitrary files to the target's filesystem. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04: mercurial 4.8.2-1ubuntu3.19.04.1 mercurial-common 4.8.2-1ubuntu3.19.04.1 In general, a standard system update will make all the necessary changes. References: https://usn.ubuntu.com/4086-1 CVE-2019-3902 Package Information: https://launchpad.net/ubuntu/+source/mercurial/4.8.2-1ubuntu3.19.04.1