Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9462

Опубликовано: 29 дек. 2014
Источник: redhat
CVSS2: 6.5
EPSS Низкий

Описание

The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.

Отчет

Red Hat Product Security has rated this issue as having moderate security impact. This issue is not currently planned to be addressed in future updates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6mercurialWill not fix
Red Hat Enterprise Linux 7mercurialWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1204807mercurial: command Injection via sshpeer._validaterepo()

EPSS

Процентиль: 90%
0.04169
Низкий

6.5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.

nvd
больше 11 лет назад

The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.

debian
больше 11 лет назад

The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows ...

suse-cvrf
больше 11 лет назад

Security update for mercurial

suse-cvrf
больше 11 лет назад

Security update for mercurial

EPSS

Процентиль: 90%
0.04169
Низкий

6.5 Medium

CVSS2