GHSA-9xv4-r2hf-26gh
Dashboard / Vulnerabilities / GHSA-9xv4-r2hf-26gh
GHSA-9xv4-r2hf-26gh
Summary: Mercurial Improper Input Validation vulnerability
Details: The `mpatch_apply` function in `mpatch.c` in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-13346, https://access.redhat.com/errata/RHSA-2019:2276, https://github.com/pypa/advisory-database/tree/main/vulns/mercurial/PYSEC-2018-88.yaml, https://lists.debian.org/debian-lts-announce/2020/07/msg00032.html, https://www.mercurial-scm.org/repo/hg/rev/faa924469635, https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.6.1_.282018-06-06.29
Affected packages
Package
Name: mercurial
Purl: pkg:pypi/mercurial
Affected ranges
Type: ECOSYSTEM
Events:
