Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 624726 - dev-vcs/mercurial: arbitrary code excecution through python debbuger
Summary: dev-vcs/mercurial: arbitrary code excecution through python debbuger
Status: RESOLVED DUPLICATE of bug 621068
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal critical (vote)
Assignee: Gentoo Security
URL: https://www.cvedetails.com/cve/CVE-20...
Whiteboard: C0 [stable]
Keywords: STABLEREQ
Depends on:
Blocks:
 
Reported: 2017-07-12 17:30 UTC by Christopher Díaz Riveros (RETIRED)
Modified: 2017-07-21 13:39 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-07-12 17:30:37 UTC
From $URL

Confidentiality Impact	Complete (There is total information disclosure, resulting in all system files being revealed.)
Integrity Impact	Complete (There is a total compromise of system integrity. There is a complete loss of system protection, resulting in the entire system being compromised.)
Availability Impact	Complete (There is a total shutdown of the affected resource. The attacker can render the resource completely unavailable.)
Access Complexity	Low (Specialized access conditions or extenuating circumstances do not exist. Very little knowledge or skill is required to exploit. )
Authentication	Single system (The vulnerability requires an attacker to be logged into the system (such as at a command line or via a desktop session or web interface).)
Gained Access	Admin
Vulnerability Type(s)	Execute Code

References:

https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.1.3_.282017-4-18.29 
https://www.mercurial-scm.org/repo/hg/rev/77eaf9539499 
https://bugs.debian.org/861243 
http://www.securityfocus.com/bid/99123
Comment 1 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-07-21 12:43:38 UTC
Thanks Polynomial-c for bumping the next version, hppa stills in 3.8.4. Could you please let us know if the bug affects that version, if not we could move on to the GLSA.

Thanks
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2017-07-21 13:39:54 UTC

*** This bug has been marked as a duplicate of bug 621068 ***