Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Untriaged
created 1 month ago
Mercurial before 1.6.4 fails to verify the Common Name field …

Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack.

Affected products

mercurial
  • ==1.6.4

Matching in nixpkgs

pkgs.mercurial

Fast, lightweight SCM system for very large distributed projects

Package maintainers