Debian Linux Security Advisory 3257-1 - Jesse Hertz of Matasano Security discovered that Mercurial, a distributed version control system, is prone to a command injection vulnerability via a crafted repository name in a clone command.
02fe64a48244b978d7f1327c1a23939a2e5bc17dfe9f02308bd91d946782c3de