PT-2019-5751 · Mercurial+3 · Mercurial+3

Pedro Sampaio

·

Publicado

2019-03-06

·

Atualizado

2024-06-15

·

CVE-2019-3902

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mercurial versions prior to 4.9
Description A flaw was found in Mercurial that allows an attacker to use symlinks and subrepositories to defeat Mercurial's path-checking logic, potentially writing files outside a repository. This issue is related to incorrect link resolution before accessing a file, which could allow a remote attacker to compromise data integrity and cause a denial of service.
Recommendations For Mercurial versions prior to 4.9, update to version 4.9 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Correção

Link Following

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1358
BDU:2021-01319
CVE-2019-3902
DLA-1764-1
DLA-2293-1
GHSA-MQ66-VCFC-8246
MGASA-2019-0250
OPENSUSE-SU-2020:0869-1
OPENSUSE-SU-2020:0880-1
OPENSUSE-SU-2020_0869-1
OPENSUSE-SU-2020_0880-1
OPENSUSE-SU-2024:10586-1
PYSEC-2019-188
SUSE-SU-2020:1709-1
SUSE-SU-2020:1709-2
SUSE-SU-2020:3003-1
SUSE-SU-2020_1709-1
SUSE-SU-2020_1709-2
SUSE-SU-2020_3003-1
USN-4086-1
USN-5102-1
USN-5102-2

Produtos afetados

Alt Linux
Mercurial
Suse
Ubuntu