Description
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1764-1 | mercurial security update |
Debian DLA |
DLA-2293-1 | mercurial security update |
EUVD |
EUVD-2019-0085 | A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository. |
Github GHSA |
GHSA-mq66-vcfc-8246 | Mercurial Path Traversal/Link Following vulnerability |
Ubuntu USN |
USN-4086-1 | Mercurial vulnerability |
Ubuntu USN |
USN-5102-1 | Mercurial vulnerabilities |
Ubuntu USN |
USN-5102-2 | Mercurial vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T19:26:26.699Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3902
No data.
Status : Modified
Published: 2019-04-22T16:29:01.913
Modified: 2024-11-21T04:42:49.947
Link: CVE-2019-3902
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN