MGASA-2018-0355

Source
https://advisories.mageia.org/MGASA-2018-0355.html
Import Source
https://advisories.mageia.org/MGASA-2018-0355.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2018-0355
Related
Published
2018-08-31T21:11:59Z
Modified
2018-08-31T20:23:49Z
Summary
Updated mercurial packages fix security vulnerabilities
Details

This update provides mercurial version 4.6.2 and fixes the following security issues:

Fix the mpatch_apply function in mpatch.c that incorrectly proceeds in cases where the fragment start is past the end of the original data (CVE-2018-13346).

Fix mpatch.c that mishandles integer addition and subtraction (CVE-2018-13347).

Fix the mpatch_decode function in mpatch.c that mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data (CVE-2018-13348).

Remote attackers may bypass HTTP server permissions via batch wire protocol commands(CVE-2018-1000132).

References
Credits

Affected packages

Mageia:5 / mercurial

Package

Name
mercurial
Purl
pkg:rpm/mageia/mercurial?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.6.2-1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / mercurial

Package

Name
mercurial
Purl
pkg:rpm/mageia/mercurial?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.6.2-1.mga6

Ecosystem specific

{
    "section": "core"
}