In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name. Reference: https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.1.3_.282017-4-18.29 Upstream patch: https://www.mercurial-scm.org/repo/hg/rev/77eaf9539499
Created mercurial tracking bugs for this issue: Affects: fedora-all [bug 1459485]
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 Via RHSA-2017:1576 https://access.redhat.com/errata/RHSA-2017:1576