MGASA-2019-0250 - Updated mercurial packages fix security vulnerability

Publication date: 06 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0250.html
Type: security
Affected Mageia releases: 6, 7
CVE: CVE-2019-3902

It was discovered that Mercurial mishandled symlinks in subrepositories.
An attacker could use this vulnerability to write arbitrary files to the
target’s filesystem (CVE-2019-3902).

References:
- https://bugs.mageia.org/show_bug.cgi?id=25291
- https://ubuntu.com/security/notices/USN-4086-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3902

SRPMS:
- 6/core/mercurial-4.9.1-1.mga6
- 7/core/mercurial-4.9.1-1.mga7

Mageia 2019-0250: mercurial security update

It was discovered that Mercurial mishandled symlinks in subrepositories

Summary

It was discovered that Mercurial mishandled symlinks in subrepositories. An attacker could use this vulnerability to write arbitrary files to the target’s filesystem (CVE-2019-3902).

References

- https://bugs.mageia.org/show_bug.cgi?id=25291

- https://ubuntu.com/security/notices/USN-4086-1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3902

Resolution

MGASA-2019-0250 - Updated mercurial packages fix security vulnerability

SRPMS

- 6/core/mercurial-4.9.1-1.mga6

- 7/core/mercurial-4.9.1-1.mga7

Severity
Publication date: 06 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0250.html
Type: security
CVE: CVE-2019-3902

Related News