Skip to content

Commit

Permalink
docs: add note about potential security issue in 4.7.2
Browse files Browse the repository at this point in the history
  • Loading branch information
indygreg committed Oct 31, 2018
1 parent fa44469 commit 267796a
Showing 1 changed file with 4 additions and 1 deletion.
5 changes: 4 additions & 1 deletion docs/hgmozilla/installing.rst
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,10 @@ latest stable release is always listed at
could result in arbitrary client-side code execution when pulling
from repositories.

Version 4.6.1 or newer should always be used.
Mercurial versions before 4.7.2 have a possible out-of-bounds memory
access that could result in security issues.

Version 4.7.2 or newer should always be used.

Mercurial makes a major *X.Y* release every three months, typically around
the first of the month. Release months are February, May, August, and
Expand Down

0 comments on commit 267796a

Please sign in to comment.