Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-3902

Опубликовано: 22 апр. 2019
Источник: debian

Описание

A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mercurialfixed4.9-1package
mercurialfixed4.8.2-1+deb10u1busterpackage

Примечания

  • https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.9_.282019-02-01.29

  • https://www.mercurial-scm.org/repo/hg/rev/6c10eba6b9cd

  • https://www.mercurial-scm.org/repo/hg/rev/31286c9282df

  • https://www.mercurial-scm.org/repo/hg/rev/83377b4b4ae0

Связанные уязвимости

CVSS3: 5.1
ubuntu
почти 7 лет назад

A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.

CVSS3: 5.1
redhat
почти 7 лет назад

A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.

CVSS3: 5.1
nvd
почти 7 лет назад

A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.

suse-cvrf
больше 5 лет назад

Security update for mercurial

suse-cvrf
больше 5 лет назад

Security update for mercurial