Candidate: CVE-2016-3068 PublicDate: 2016-04-13 16:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3068 https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.7.3_.282016-3-29.29 https://selenic.com/repo/hg-stable/rev/34d43cb85de8 Description: Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository. Ubuntu-Description: It was discovered that Mercurial incorrectly handled git ext:: URL. An attacker could possibly use this issue to execute arbitrary code. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=819504 Priority: medium Discovered-by: Blake Burkhart Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_mercurial: upstream_mercurial: released (3.7.3-1) precise_mercurial: ignored (reached end-of-life) precise/esm_mercurial: DNE (precise was needed) trusty_mercurial: released (2.8.2-1ubuntu1.4) trusty/esm_mercurial: released (2.8.2-1ubuntu1.4) vivid/stable-phone-overlay_mercurial: DNE vivid/ubuntu-core_mercurial: DNE wily_mercurial: ignored (reached end-of-life) xenial_mercurial: not-affected (3.7.3-1ubuntu1) yakkety_mercurial: not-affected (3.7.3-1ubuntu1) zesty_mercurial: not-affected (3.7.3-1ubuntu1) artful_mercurial: not-affected (3.7.3-1ubuntu1) bionic_mercurial: not-affected (3.7.3-1ubuntu1) cosmic_mercurial: not-affected (3.7.3-1ubuntu1) devel_mercurial: not-affected (3.7.3-1ubuntu1)