CRITICAL
mercurial: command injection on clients through malicious ssh URLs
Published Oct 4, 2017
9.3
CRITICALCVSS 4.0
EPSS 6.29%
Description
Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
Affected products
No data.
Configuration 2
OR
- 8.0
- 9.0
Configuration 3
OR
- 7.0
- 7.0
- 7.4
- 7.6
- 7.4
- 7.5
- 7.6
- 7.4
- 7.6
- 7.0
No data.
Red Hat Enterprise Linux 7
mercurial-0:2.6.2-8.el7_4
Fixed · RHSA-2017:2489
Red Hat Enterprise Linux 6
mercurial
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | mercurial-0:2.6.2-8.el7_4 | Fixed | RHSA-2017:2489 |
| Red Hat Enterprise Linux 6 | mercurial | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (13)
- http://www.debian.org/security/2017/dsa-3963 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.securityfocus.com/bid/100290 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:2489 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-1000116 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1479915 Issue Tracking
- https://github.com/advisories/GHSA-3qmg-c9vc-r47j Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/mercurial/PYSEC-2017-89.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000116
- https://security.gentoo.org/glsa/201709-18 vendor-advisoryx_refsource_GENTOOPatchThird Party AdvisoryVDB Entry
- https://web.archive.org/web/20200227155758/http://www.securityfocus.com/bid/100290
- https://wiki.mercurial-scm.org/WhatsNew/Archive
- https://www.cve.org/CVERecord?id=CVE-2017-1000116
- https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.3_.2F_4.3.1_.282017-08-10.29 x_refsource_CONFIRMRelease NotesVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 4, 2017
Updated Aug 5, 2024
Reserved Oct 3, 2017
Link CVE-2017-1000116
CISA Vulnrichment
GHSA-3QMG-C9VC-R47J Updated n/a