HIGH
Mercurial: pathaudit: path traversal via symlink
Published Oct 4, 2017
8.7
HIGHCVSS 4.0
EPSS 4.81%
Description
Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository
Affected products
No data.
Configuration 2
OR
- 8.0
- 9.0
Configuration 3
OR
- 7.0
- 7.0
- 7.4
- 7.6
- 7.4
- 7.5
- 7.6
- 7.4
- 7.6
- 7.0
No data.
Red Hat Enterprise Linux 7
mercurial-0:2.6.2-8.el7_4
Fixed · RHSA-2017:2489
Red Hat Enterprise Linux 6
mercurial
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | mercurial-0:2.6.2-8.el7_4 | Fixed | RHSA-2017:2489 |
| Red Hat Enterprise Linux 6 | mercurial | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (13)
- http://www.debian.org/security/2017/dsa-3963 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.securityfocus.com/bid/100290 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:2489 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-1000115 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1480330 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-0070 Advisory
- https://github.com/advisories/GHSA-hvr9-wr9p-grgr Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/mercurial/PYSEC-2017-88.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000115
- https://security.gentoo.org/glsa/201709-18 vendor-advisoryx_refsource_GENTOOThird Party AdvisoryVDB Entry
- https://web.archive.org/web/20200227155758/http://www.securityfocus.com/bid/100290
- https://www.cve.org/CVERecord?id=CVE-2017-1000115
- https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.3_.2F_4.3.1_.282017-08-10.29 x_refsource_CONFIRMRelease NotesVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 4, 2017
Updated Aug 5, 2024
Reserved Oct 3, 2017
Link CVE-2017-1000115
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2017-0070 GHSA-HVR9-WR9P-GRGR Assigner mitre
Published Oct 4, 2017
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2017-0070