CVE-2008-2942

unknown
Published 2022-05-01 ยท Modified 2024-12-03
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
โ€”

Description

Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2008-2942 NameCVE-2008-2942 DescriptionDirectory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Debian Bugs488628โ€ฆ

CVE-2008-2942

NameCVE-2008-2942
DescriptionDirectory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs488628

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mercurial (PTS)bullseye5.6.1-4fixed
bullseye (security)5.6.1-4+deb11u1fixed
bookworm, bookworm (security)6.3.2-1+deb12u1fixed
trixie7.0.1-2fixed
forky7.2-5fixed
sid7.2.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mercurialsourceetch(not affected)
mercurialsource(unstable)1.0.1-2low488628

Notes

[etch] - mercurial <not-affected> (Vulnerable functionality not present)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[etch] - mercurial <not-affected> (Vulnerable functionality not present)

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1.0.1-2
sid Fixed 1.0.1-2
forky Fixed 1.0.1-2
bullseye Fixed 1.0.1-2
bookworm Fixed 1.0.1-2

Package impact

EcosystemPackageVulnerableFixed
python PyPImercurial<1.0.21.0.2

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.