Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Debian Wheezy DLA-1072-1 Critical: Mercurial Shell Injection Fix

debian lts
Calendar Grey August 31, 2017
Scroller Debian Lts
Recent findings reveal two security gaps within Mercurial that pose risks of shell injection and file overwriting. Ensure your systems are updated immediately to maintain security.
Two significant vulnerabilities were found in the Mercurial version control system which could lead to shell injection attacks and out-of-tree file overwrite

Summary

CVE-2017-1000115

Mercurial's symlink auditing was incomplete prior to 4.3, and
could be abused to write to files outside the repository.

CVE-2017-1000116

Mercurial was not sanitizing hostnames passed to ssh, allowing
shell injection attacks on clients by specifying a hostname
starting with -oProxyCommand. This vulnerability is similar to
those in Git (CVE-2017-1000117) and Subversion (CVE-2017-9800).

For Debian 7 "Wheezy", these problems have been fixed in version
2.2.2-4+deb7u5.

We recommend that you upgrade your mercurial packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: mercurial
Version: 2.2.2-4+deb7u5
CVE ID: CVE-2017-1000115 CVE-2017-1000116
Debian Bug: 871709 871710

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.