OS Command Injection
Affecting mercurial package, versions <3.1.2-2+deb8u4
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
References
CVSS Score
9.8
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2017-1000116
- CWE
- CWE-78
- Snyk ID
- SNYK-DEBIAN8-MERCURIAL-311037
- Disclosed
- 05 Oct, 2017
- Published
- 05 Oct, 2017