Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1000132

Опубликовано: 14 мар. 2018
Источник: debian
EPSS Низкий

Описание

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mercurialfixed4.5.2-1package

Примечания

  • https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.5.1_.2F_4.5.2_.282018-03-06.29

  • https://www.mercurial-scm.org/repo/hg/rev/2ecb0fc535b1 (4.5.2)

  • Backports for older branches in https://hg.mozilla.org/users/gszorc_mozilla.com/hg

  • 4.4: 4843835c835::7cf827e5f8af

  • 4.3: db527ae12671::86f9a022ccb8

EPSS

Процентиль: 73%
0.00783
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
почти 8 лет назад

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.

CVSS3: 6.5
redhat
почти 8 лет назад

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.

CVSS3: 9.1
nvd
почти 8 лет назад

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.

suse-cvrf
почти 8 лет назад

Security update for mercurial

suse-cvrf
почти 8 лет назад

Security update for mercurial

EPSS

Процентиль: 73%
0.00783
Низкий