Debian DSA-3542-1 : mercurial - security update

high Nessus Plugin ID 90370

Synopsis

The remote Debian host is missing a security-related update.

Description

Several vulnerabilities have been discovered in Mercurial, a distributed version control system. The Common Vulnerabilities and Exposures project identifies the following issues :

- CVE-2016-3068 Blake Burkhart discovered that Mercurial allows URLs for Git subrepositories that could result in arbitrary code execution on clone.

- CVE-2016-3069 Blake Burkhart discovered that Mercurial allows arbitrary code execution when converting Git repositories with specially crafted names.

- CVE-2016-3630 It was discovered that Mercurial does not properly perform bounds-checking in its binary delta decoder, which may be exploitable for remote code execution via clone, push or pull.

Solution

Upgrade the mercurial packages.

For the oldstable distribution (wheezy), these problems have been fixed in version 2.2.2-4+deb7u2.

For the stable distribution (jessie), these problems have been fixed in version 3.1.2-2+deb8u2.

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=819504

https://security-tracker.debian.org/tracker/CVE-2016-3068

https://security-tracker.debian.org/tracker/CVE-2016-3069

https://security-tracker.debian.org/tracker/CVE-2016-3630

https://packages.debian.org/source/wheezy/mercurial

https://packages.debian.org/source/jessie/mercurial

https://www.debian.org/security/2016/dsa-3542

Plugin Details

Severity: High

ID: 90370

File Name: debian_DSA-3542.nasl

Version: 2.10

Type: local

Agent: unix

Published: 4/7/2016

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:mercurial, cpe:/o:debian:debian_linux:7.0, cpe:/o:debian:debian_linux:8.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 4/5/2016

Reference Information

CVE: CVE-2016-3068, CVE-2016-3069, CVE-2016-3630

DSA: 3542