SB2016041915 - Data Handling in mercurial (Alpine package)
Published: April 19, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Data Handling (CVE-ID: CVE-2016-3630)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=5bafcce1dd15bf47e71e22042af62ece632ebe5d
- https://git.alpinelinux.org/aports/commit/?id=91ff36fbe7831bd7f8575b28cb8063cae27405ed
- https://git.alpinelinux.org/aports/commit/?id=d5e04dc629fe4e4681aaefb867f716db5abf2170
- https://git.alpinelinux.org/aports/commit/?id=43622bb26d2e04aa61ae8bfb905ebe671b8abf10