Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:2023-1

Опубликовано: 19 июл. 2018
Источник: suse-cvrf

Описание

Security update for mercurial

This update for mercurial fixes the following issues:

Security issues fixed:

  • CVE-2018-13348: Fix the mpatch_decode function in mpatch.c that mishandles certain situations where there should be at least 12 bytes remaining after thecurrent position in the patch data (boo#1100353).
  • CVE-2018-13347: Fix mpatch.c that mishandles integer addition and subtraction (boo#1100355).
  • CVE-2018-13346: Fix the mpatch_apply function in mpatch.c that incorrectly proceeds in cases where the fragment start is past the end of the original data (boo#1100354).

Список пакетов

openSUSE Leap 42.3
mercurial-4.2.3-15.1
mercurial-lang-4.2.3-15.1

Описание

The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004.


Затронутые продукты
openSUSE Leap 42.3:mercurial-4.2.3-15.1
openSUSE Leap 42.3:mercurial-lang-4.2.3-15.1

Ссылки

Описание

mpatch.c in Mercurial before 4.6.1 mishandles integer addition and subtraction, aka OVE-20180430-0002.


Затронутые продукты
openSUSE Leap 42.3:mercurial-4.2.3-15.1
openSUSE Leap 42.3:mercurial-lang-4.2.3-15.1

Ссылки

Описание

The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.


Затронутые продукты
openSUSE Leap 42.3:mercurial-4.2.3-15.1
openSUSE Leap 42.3:mercurial-lang-4.2.3-15.1

Ссылки