CVE-2016-3105 PUBLISHED

The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.

EPSS 1.18% · 78.6th percentile

Risk Scores

EPSS Score
1.18%
78.6th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSmercurial0, 2.6.3-1, 2.7.2-1
Ubuntu:16.04:LTSmercurial0, 3.4-1ubuntu2, 3.6.2-1ubuntu2

Timeline

References

Open in Interactive Console →