VDB

ALINUX2-SA-2019%3A0077

ALINUX2-SA-2019%3A0077 PUBLISHED CVSS 4.300000190734863 MEDIUM

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2018-1000132: Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1. CVE-2018-13346: The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004. CVE-2018-13347: mpatch.c in Mercurial before 4.6.1 mishandles integer addition and subtraction, aka OVE-20180430-0002.

Risk Scores

CVSS 3.0
4.300000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersions
Alibaba Cloudmercurial

Timeline

  • Oct 9, 2019 CVE Published
  • Oct 9, 2019 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›