Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2017:2250-1

Опубликовано: 24 авг. 2017
Источник: suse-cvrf

Описание

Security update for mercurial

This update for mercurial fixes the following issues:

  • CVE-2017-1000115: path traversal via symlink could lead to unauthorized access (bsc#1053344)
  • CVE-2017-1000116: argument injection in SSH URLs could lead to client-side code execution (bsc#1052696)

Список пакетов

SUSE Linux Enterprise Software Development Kit 11 SP4
mercurial-2.3.2-0.18.3.1

Описание

Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository


Затронутые продукты
SUSE Linux Enterprise Software Development Kit 11 SP4:mercurial-2.3.2-0.18.3.1

Ссылки

Описание

Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.


Затронутые продукты
SUSE Linux Enterprise Software Development Kit 11 SP4:mercurial-2.3.2-0.18.3.1

Ссылки
Уязвимость SUSE-SU-2017:2250-1