Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.703570
Categoría:Debian Local Security Checks
Título:Debian Security Advisory DSA 3570-1 (mercurial - security update)
Resumen:Blake Burkhart discovered an arbitrary;code execution flaw in Mercurial, a distributed version control system, when;using the convert extension on Git repositories with specially crafted names.;This flaw in particular affects automated code conversion services that allow;arbitrary repository names.
Descripción:Summary:
Blake Burkhart discovered an arbitrary
code execution flaw in Mercurial, a distributed version control system, when
using the convert extension on Git repositories with specially crafted names.
This flaw in particular affects automated code conversion services that allow
arbitrary repository names.

Affected Software/OS:
mercurial on Debian Linux

Solution:
For the stable distribution (jessie),
this problem has been fixed in version 3.1.2-2+deb8u3.

For the unstable distribution (sid), this problem has been fixed in
version 3.8.1-1.

We recommend that you upgrade your mercurial packages.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-3105
BugTraq ID: 90536
http://www.securityfocus.com/bid/90536
Debian Security Information: DSA-3570 (Google Search)
http://www.debian.org/security/2016/dsa-3570
https://security.gentoo.org/glsa/201612-19
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.533255
SuSE Security Announcement: openSUSE-SU-2016:1336 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-05/msg00082.html
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.