SB2016041915 - Data Handling in mercurial (Alpine package)
Published: April 19, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Data Handling (CVE-ID: CVE-2016-3630)
CWE-ID: CWE-19 - Data Handling
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=5bafcce1dd15bf47e71e22042af62ece632ebe5d
- https://git.alpinelinux.org/aports/commit/?id=91ff36fbe7831bd7f8575b28cb8063cae27405ed
- https://git.alpinelinux.org/aports/commit/?id=d5e04dc629fe4e4681aaefb867f716db5abf2170
- https://git.alpinelinux.org/aports/commit/?id=43622bb26d2e04aa61ae8bfb905ebe671b8abf10