UBUNTU-CVE-2017-17458
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-17458
Summary:
Details: In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.
References: https://ubuntu.com/security/CVE-2017-17458, https://bz.mercurial-scm.org/show_bug.cgi?id=5730, https://www.mercurial-scm.org/pipermail/mercurial-devel/2017-November/107333.html, https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.4.1_.282017-11-07.29, https://www.cve.org/CVERecord?id=CVE-2017-17458
Affected packages
Package
Name: mercurial
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
