Wind River Support Network

HomeDefectsLIN7-9267
Fixed

LIN7-9267 : Security Advisory - mercurial - CVE-2017-17458

Created: Dec 14, 2017    Updated: Sep 8, 2018
Resolved Date: Jan 17, 2018
Found In Version: 7.0.0.27
Fix Version: 7.0.0.28
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.

https://nvd.nist.gov/vuln/detail/CVE-2017-17458

Other Downloads


CVEs


Live chat
Online