Lucene search

K
mageiaGentoo FoundationMGASA-2015-0129
HistoryApr 03, 2015 - 4:11 p.m.

Updated mercurial packages fix CVE-2014-9462

2015-04-0316:11:23
Gentoo Foundation
advisories.mageia.org
13

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.038 Low

EPSS

Percentile

91.9%

Updated mercurial packages fix security vulnerability: The mercurial source code management system suffers from a code-injection flaw due to insufficient shell quoting in sshpeer._validaterepo() (CVE-2014-9462).

OSVersionArchitecturePackageVersionFilename
Mageia4noarchmercurial< 2.7.2-3.1mercurial-2.7.2-3.1.mga4

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.038 Low

EPSS

Percentile

91.9%