Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-17458

Опубликовано: 07 дек. 2017
Источник: ubuntu
Приоритет: medium
CVSS2: 10
CVSS3: 9.8

Описание

In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

cosmic

not-affected

devel

not-affected

esm-apps/bionic

not-affected

esm-apps/xenial

released

3.7.3-1ubuntu1.1
esm-infra-legacy/trusty

released

2.8.2-1ubuntu1.4
precise/esm

DNE

trusty

released

2.8.2-1ubuntu1.4
trusty/esm

released

2.8.2-1ubuntu1.4

Показывать по

10 Critical

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 6.3
redhat
больше 8 лет назад

In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.

CVSS3: 9.8
nvd
около 8 лет назад

In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.

CVSS3: 9.8
debian
около 8 лет назад

In Mercurial before 4.4.1, it is possible that a specially malformed r ...

suse-cvrf
около 8 лет назад

Security update for mercurial

suse-cvrf
около 8 лет назад

Security update for mercurial

10 Critical

CVSS2

9.8 Critical

CVSS3