Fedora Account System
Red Hat Associate
Red Hat Customer
The symlink auditor is sometimes cached too long, and can be confused into allowing write access to outside the repo.
External References: https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.3_.2F_4.3.1_.282017-08-10.29
Acknowledgments: Name: the Mercurial Security Team
Created mercurial tracking bugs for this issue: Affects: fedora-all [bug 1480454]
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:2489 https://access.redhat.com/errata/RHSA-2017:2489