Bugzilla – Bug 1133035
VUL-1: CVE-2019-3902: mercurial: use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
Last modified: 2024-05-07 09:06:51 UTC
CONFIRM:bugzilla.redhat.com:CVE-2019-3902 A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository. References: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3902 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-3902 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-3902.html http://www.cvedetails.com/cve/CVE-2019-3902/ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3902
Backported to relevant branches. Reassigning back to security team.
I failed to find a reproducer, will skip the bug verification.
SUSE-SU-2020:1709-1: An update that fixes one vulnerability is now available. Category: security (low) Bug References: 1133035 CVE References: CVE-2019-3902 Sources used: SUSE Linux Enterprise Module for Python2 15-SP1 (src): mercurial-4.5.2-3.9.44 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2020:0869-1: An update that fixes one vulnerability is now available. Category: security (low) Bug References: 1133035 CVE References: CVE-2019-3902 Sources used: openSUSE Leap 15.1 (src): mercurial-4.5.2-lp151.6.3.1
openSUSE-SU-2020:0880-1: An update that fixes one vulnerability is now available. Category: security (low) Bug References: 1133035 CVE References: CVE-2019-3902 Sources used: openSUSE Leap 15.2 (src): mercurial-4.5.2-lp152.7.3.1
SUSE-SU-2020:1709-2: An update that fixes one vulnerability is now available. Category: security (low) Bug References: 1133035 CVE References: CVE-2019-3902 Sources used: SUSE Linux Enterprise Module for Python2 15-SP2 (src): mercurial-4.5.2-3.9.44 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2020:3003-1: An update that fixes one vulnerability is now available. Category: security (low) Bug References: 1133035 CVE References: CVE-2019-3902 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): mercurial-2.8.2-15.18.4 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
All done, closing.