Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-13348

Опубликовано: 06 июн. 2018
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Tower 3mercurialNot affected
Red Hat Enterprise Linux 6mercurialNot affected
Red Hat Enterprise Linux 7mercurialNot affected
Red Hat Enterprise Linux 8mercurialNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=1594083mercurial: Improper length check in mpatch.c

EPSS

Процентиль: 80%
0.02104
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.

CVSS3: 7.5
nvd
около 8 лет назад

The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.

CVSS3: 7.5
debian
около 8 лет назад

The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 misha ...

CVSS3: 7.5
github
больше 4 лет назад

Mercurial Improper Input Validation vulnerability

CVSS3: 7.5
fstec
около 8 лет назад

Уязвимость функции mpatch_decode программного средства управления версиями Mercuria, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 80%
0.02104
Низкий

4.3 Medium

CVSS3