PT-2018-14313 · Mercurial+3 · Mercurial+3

Yuya Nishihara

·

Published

2018-10-04

·

Updated

2024-06-15

·

CVE-2018-17983

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mercurial versions prior to 4.7.2
Description The issue is related to an out-of-bounds read that occurs during the parsing of a malformed manifest entry in the cext/manifest.c file. This can potentially lead to information disclosure or other security issues.
Recommendations For Mercurial versions prior to 4.7.2, update to version 4.7.2 or later to resolve the issue. As a temporary workaround, consider restricting access to malformed manifest entries until the update is applied.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2508
CVE-2018-17983
GHSA-P575-CF9H-WV42
MGASA-2018-0442
OPENSUSE-SU-2018_3517-1
OPENSUSE-SU-2024:10586-1
PYSEC-2018-91
SUSE-SU-2018:3430-1
SUSE-SU-2018_3430-1
USN-5102-1
USN-5102-2

Affected Products

Alt Linux
Mercurial
Suse
Ubuntu