VDB

CVE-2018-13346

CVE-2018-13346 PUBLISHED

The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004.

EPSS 0.29% · 52.6th percentile

Risk Scores

EPSS Score
0.29%
52.6th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSmercurial2.8.1-2, 2.8.2-1ubuntu1, 2.8.2-1ubuntu1.3
Ubuntu:16.04:LTSmercurial3.6.2-1ubuntu2, 3.7.3-1ubuntu1, 3.4-1ubuntu2
Ubuntu:18.04:LTSmercurial4.5-1ubuntu1, 4.5.2-0ubuntu2, 4.5.3-1ubuntu2

Timeline

  • Jul 6, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›