Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-4297

Опубликовано: 27 сент. 2008
Источник: ubuntu
Приоритет: negligible
CVSS2: 5

Описание

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.

РелизСтатусПримечание
dapper

ignored

devel

not-affected

feisty

ignored

gutsy

ignored

hardy

ignored

upstream

released

1.0.2

Показывать по

Ссылки на источники

5 Medium

CVSS2

Связанные уязвимости

redhat
около 17 лет назад

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.

nvd
почти 17 лет назад

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.

debian
почти 17 лет назад

Mercurial before 1.0.2 does not enforce the allowpull permission setti ...

github
больше 3 лет назад

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.

5 Medium

CVSS2