Gentoo Linux Security Advisory 201612-19 - Multiple vulnerabilities have been found in Mercurial, the worst of which could lead to the remote execution of arbitrary code. Versions less than 3.8.4 are affected.
47c379d973e4969784c5bccded8e80c7573e79b6ec6f68d82c36130813ba786e
Debian Linux Security Advisory 3257-1 - Jesse Hertz of Matasano Security discovered that Mercurial, a distributed version control system, is prone to a command injection vulnerability via a crafted repository name in a clone command.
02fe64a48244b978d7f1327c1a23939a2e5bc17dfe9f02308bd91d946782c3de