MGASA-2018-0355

Source
https://advisories.mageia.org/MGASA-2018-0355.html
Import Source
https://advisories.mageia.org/MGASA-2018-0355.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2018-0355
Related
Published
2018-08-31T21:11:59Z
Modified
2018-08-31T20:23:49Z
Summary
Updated mercurial packages fix security vulnerabilities
Details

This update provides mercurial version 4.6.2 and fixes the following security issues:

Fix the mpatch_apply function in mpatch.c that incorrectly proceeds in cases where the fragment start is past the end of the original data (CVE-2018-13346).

Fix mpatch.c that mishandles integer addition and subtraction (CVE-2018-13347).

Fix the mpatch_decode function in mpatch.c that mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data (CVE-2018-13348).

Remote attackers may bypass HTTP server permissions via batch wire protocol commands(CVE-2018-1000132).

References
Credits

Affected packages