Lucene search

K
redhatRedHatRHSA-2016:0706
HistoryMay 02, 2016 - 12:16 p.m.

(RHSA-2016:0706) Important: mercurial security update

2016-05-0212:16:03
access.redhat.com
12

EPSS

0.053

Percentile

93.1%

Mercurial is a fast, lightweight source control management system designed for efficient handling of very large distributed projects.

Security Fix(es):

  • It was discovered that Mercurial failed to properly check Git sub-repository URLs. A Mercurial repository that includes a Git sub-repository with a specially crafted URL could cause Mercurial to execute arbitrary code. (CVE-2016-3068)

  • It was discovered that the Mercurial convert extension failed to sanitize special characters in Git repository names. A Git repository with a specially crafted name could cause Mercurial to execute arbitrary code when the Git repository was converted to a Mercurial repository. (CVE-2016-3069)

Red Hat would like to thank Blake Burkhart for reporting these issues.