mercurial is vulnerable to buffer underflows. The application does not validate the pointer position when reading a patch fragment, allowing a malicious user to cause a buffer underflow by passing a patch file to the application, causing the application to crash or arbitrary code to be executed.
CPE | Name | Operator | Version |
---|---|---|---|
mercurial | le | 4.6 | |
mercurial:stretch | eq | 4.0-1+deb9u1 |
access.redhat.com/errata/RHSA-2019:2276
lists.debian.org/debian-lts-announce/2020/07/msg00032.html
www.mercurial-scm.org/repo/hg-committed/log?rev=modifies%28%22mercurial%2Fmpatch.c%22%29+and+4.5%3A%3A
www.mercurial-scm.org/repo/hg/rev/1acfc35d478c
www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.6.1_.282018-06-06.29