Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3105

Опубликовано: 06 апр. 2016
Источник: redhat
CVSS2: 5.1

Описание

The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.

It was discovered that the Mercurial convert extension invoked Git in a way that could cause Git to interpret local repository name as remote repository URL. A Git repository with a specially crafted name could cause Mercurial to execute arbitrary code when the Git repository was converted to a Mercurial repository.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6mercurialWill not fix
Red Hat Enterprise Linux 7mercurialWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1332945mercurial: arbitrary code execution when converting git repos

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 9 лет назад

The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.

CVSS3: 8.8
nvd
больше 9 лет назад

The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.

CVSS3: 8.8
debian
больше 9 лет назад

The convert extension in Mercurial before 3.8 might allow context-depe ...

suse-cvrf
больше 9 лет назад

Security update for mercurial

suse-cvrf
больше 9 лет назад

Security update for mercurial

5.1 Medium

CVSS2