Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-13348

Опубликовано: 06 июл. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.

РелизСтатусПримечание
artful

ignored

end of life
bionic

released

4.5.3-1ubuntu2.1
cosmic

not-affected

4.6.1-1ubuntu1
devel

not-affected

4.6.1-1ubuntu1
esm-apps/bionic

released

4.5.3-1ubuntu2.1
esm-apps/xenial

released

3.7.3-1ubuntu1.1
esm-infra-legacy/trusty

released

2.8.2-1ubuntu1.4
precise/esm

DNE

trusty

released

2.8.2-1ubuntu1.4
trusty/esm

released

2.8.2-1ubuntu1.4

Показывать по

EPSS

Процентиль: 69%
0.00613
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 4.3
redhat
больше 7 лет назад

The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.

CVSS3: 7.5
nvd
больше 7 лет назад

The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.

CVSS3: 7.5
debian
больше 7 лет назад

The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 misha ...

CVSS3: 7.5
github
больше 3 лет назад

Mercurial Improper Input Validation vulnerability

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость функции mpatch_decode программного средства управления версиями Mercuria, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 69%
0.00613
Низкий

5 Medium

CVSS2

7.5 High

CVSS3