Mercurial was not sanitizing hostnames passed to ssh, allowing shell injection attacks by specifying a hostname starting with -oProxyCommand.
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2017-0331.json"