Bugzilla – Bug 973177
VUL-0: CVE-2016-3068: mercurial: arbitrary code execution with Git subrepos
Last modified: 2018-06-11 15:16:34 UTC
rh#1322266 Mercurial prior to 3.7.3 allowed URLs for Git subrepos that could result in arbitrary code execution on clone. This is a further side-effect of Git CVE-2015-7545. External references: https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.7.3_.282016-3-29.29 Upstream fix: https://selenic.com/repo/hg-stable/rev/34d43cb85de8 References: https://bugzilla.redhat.com/show_bug.cgi?id=1322266 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-3068
bugbot adjusting priority
Do we have a bug reproducer? The fixed packages are ready, but untested.
Technically there is code that tests for the problem within the commit itself (https://selenic.com/repo/hg-stable/rev/34d43cb85de8 )
This is an autogenerated message for OBS integration: This bug (973177) was mentioned in https://build.opensuse.org/request/show/384126 42.1 / mercurial https://build.opensuse.org/request/show/384129 13.2 / mercurial
Assigned back to security team.
SUSE-SU-2016:1010-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 973175,973176,973177 CVE References: CVE-2016-3068,CVE-2016-3069,CVE-2016-3630 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP1 (src): mercurial-2.8.2-6.1 SUSE Linux Enterprise Software Development Kit 12 (src): mercurial-2.8.2-6.1
SUSE-SU-2016:1011-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 973175,973176,973177 CVE References: CVE-2016-3068,CVE-2016-3069,CVE-2016-3630 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): mercurial-2.3.2-0.11.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): mercurial-2.3.2-0.11.1
openSUSE-SU-2016:1016-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 973175,973176,973177 CVE References: CVE-2016-3068,CVE-2016-3069,CVE-2016-3630 Sources used: openSUSE 13.2 (src): mercurial-3.1.2-7.1
releasing for leap 42.1
openSUSE-SU-2016:1073-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 973175,973176,973177 CVE References: CVE-2016-3068,CVE-2016-3069,CVE-2016-3630 Sources used: openSUSE Leap 42.1 (src): mercurial-3.5.1-3.1
.