Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-9462

Опубликовано: 18 апр. 2017
Источник: redhat
CVSS3: 6.3
EPSS Средний

Описание

In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.

A flaw was found in the way "hg serve --stdio" command in Mercurial handled command-line options. A remote, authenticated attacker could use this flaw to execute arbitrary code on the Mercurial server by using specially crafted command-line options.

Дополнительная информация

Статус:

Important
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1459482mercurial: Python debugger accessible to authorized users

EPSS

Процентиль: 98%
0.48699
Средний

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.

CVSS3: 8.8
nvd
больше 8 лет назад

In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.

CVSS3: 8.8
debian
больше 8 лет назад

In Mercurial before 4.1.3, "hg serve --stdio" allows remote authentica ...

suse-cvrf
больше 8 лет назад

Security update for mercurial

suse-cvrf
больше 8 лет назад

Security update for mercurial

EPSS

Процентиль: 98%
0.48699
Средний

6.3 Medium

CVSS3