PT-2019-5751 · Mercurial+3 · Mercurial+3
Pedro Sampaio
·
Publicado
2019-03-06
·
Atualizado
2024-06-15
·
CVE-2019-3902
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Mercurial versions prior to 4.9
Description
A flaw was found in Mercurial that allows an attacker to use symlinks and subrepositories to defeat Mercurial's path-checking logic, potentially writing files outside a repository. This issue is related to incorrect link resolution before accessing a file, which could allow a remote attacker to compromise data integrity and cause a denial of service.
Recommendations
For Mercurial versions prior to 4.9, update to version 4.9 or later to resolve the issue.
At the moment, there is no information about additional mitigation measures for this vulnerability.
Correção
Link Following
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Mercurial
Suse
Ubuntu