PT-2019-5751 · Mercurial+3 · Mercurial+3

Pedro Sampaio

·

Published

2019-03-06

·

Updated

2024-06-15

·

CVE-2019-3902

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mercurial versions prior to 4.9
Description A flaw was found in Mercurial that allows an attacker to use symlinks and subrepositories to defeat Mercurial's path-checking logic, potentially writing files outside a repository. This issue is related to incorrect link resolution before accessing a file, which could allow a remote attacker to compromise data integrity and cause a denial of service.
Recommendations For Mercurial versions prior to 4.9, update to version 4.9 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Fix

Link Following

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1358
BDU:2021-01319
CVE-2019-3902
DLA-1764-1
DLA-2293-1
GHSA-MQ66-VCFC-8246
MGASA-2019-0250
OPENSUSE-SU-2020:0869-1
OPENSUSE-SU-2020:0880-1
OPENSUSE-SU-2020_0869-1
OPENSUSE-SU-2020_0880-1
OPENSUSE-SU-2024:10586-1
PYSEC-2019-188
SUSE-SU-2020:1709-1
SUSE-SU-2020:1709-2
SUSE-SU-2020:3003-1
SUSE-SU-2020_1709-1
SUSE-SU-2020_1709-2
SUSE-SU-2020_3003-1
USN-4086-1
USN-5102-1
USN-5102-2

Affected Products

Alt Linux
Mercurial
Suse
Ubuntu