Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5
Описание
Mercurial missing symlink check
Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000115
- https://access.redhat.com/errata/RHSA-2017:2489
- https://github.com/pypa/advisory-database/tree/main/vulns/mercurial/PYSEC-2017-88.yaml
- https://security.gentoo.org/glsa/201709-18
- https://web.archive.org/web/20200227155758/http://www.securityfocus.com/bid/100290
- https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.3_.2F_4.3.1_.282017-08-10.29
- http://www.debian.org/security/2017/dsa-3963
Пакеты
Наименование
mercurial
pip
Затронутые версииВерсия исправления
< 4.3.1
4.3.1
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 8 лет назад
Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository
CVSS3: 5.4
redhat
больше 8 лет назад
Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository
CVSS3: 7.5
nvd
около 8 лет назад
Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository
CVSS3: 7.5
debian
около 8 лет назад
Mercurial prior to version 4.3 is vulnerable to a missing symlink chec ...