PT-2019-5751 · Mercurial+3 · Mercurial+3
Pedro Sampaio
·
Published
2019-03-06
·
Updated
2024-06-15
·
CVE-2019-3902
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Mercurial versions prior to 4.9
Description
A flaw was found in Mercurial that allows an attacker to use symlinks and subrepositories to defeat Mercurial's path-checking logic, potentially writing files outside a repository. This issue is related to incorrect link resolution before accessing a file, which could allow a remote attacker to compromise data integrity and cause a denial of service.
Recommendations
For Mercurial versions prior to 4.9, update to version 4.9 or later to resolve the issue.
At the moment, there is no information about additional mitigation measures for this vulnerability.
Fix
Link Following
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Mercurial
Suse
Ubuntu