Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia: 2019-0250 Moderate: Mercurial Symlink Write Issue

mageia
Calendar Grey September 6, 2019
Dist Mageia Esm H88
The latest security patch for Mercurial resolves a significant flaw in Mageia platforms, enhancing defense against potential dangers.
It was discovered that Mercurial mishandled symlinks in subrepositories

Summary

It was discovered that Mercurial mishandled symlinks in subrepositories. An attacker could use this vulnerability to write arbitrary files to the target’s filesystem (CVE-2019-3902).

References

- https://bugs.mageia.org/show_bug.cgi?id=25291

- https://ubuntu.com/security/notices/USN-4086-1

- https://www.cve.org/CVERecord?id=CVE-2019-3902

Resolution

SRPMS

- 6/core/mercurial-4.9.1-1.mga6

- 7/core/mercurial-4.9.1-1.mga7

Publication date: 06 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0250.html
Type: security
CVE: CVE-2019-3902

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here