Home CVE Database CVE-2016-3630



The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.

Priority: MEDIUM
CVSS v3: 8.8
Publish Date: Apr 13, 2016
Related ID: --
CVSS v2: High
Modified Date: Apr 18, 2016

Find out more about CVE-2016-3630 from the MITRE-CVE dictionary and NIST NVD

Products Affected

Login may be required to access defects or downloads.

Related Products

Product Name Status Defect Fixed Downloads
Linux 7 SCP Not Vulnerable -- -- --
Linux 7 CGP Not Vulnerable -- -- --



Live chat