Candidate: CVE-2016-3069 PublicDate: 2016-04-13 16:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3069 https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.7.3_.282016-3-29.29 https://selenic.com/repo/hg-stable/rev/197eed39e3d5 (1/5) https://selenic.com/repo/hg-stable/rev/cdda7b96afff (2/5) https://selenic.com/repo/hg-stable/rev/b732e7f2aba4 (3/5) https://selenic.com/repo/hg-stable/rev/80cac1de6aea (4/5) https://selenic.com/repo/hg-stable/rev/ae279d4a19e9 (5/5) Description: Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository. Ubuntu-Description: It was discovered that Mercurial incorrectly handled Git repository name. An attacker could possibly use this issue to execute arbitrary code. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=819504 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_mercurial: upstream_mercurial: released (3.7.3-1) precise_mercurial: ignored (reached end-of-life) precise/esm_mercurial: DNE (precise was needed) trusty_mercurial: released (2.8.2-1ubuntu1.4) trusty/esm_mercurial: released (2.8.2-1ubuntu1.4) vivid/stable-phone-overlay_mercurial: DNE vivid/ubuntu-core_mercurial: DNE wily_mercurial: ignored (reached end-of-life) xenial_mercurial: not-affected (3.7.3-1ubuntu1) yakkety_mercurial: not-affected (3.7.3-1ubuntu1) zesty_mercurial: not-affected (3.7.3-1ubuntu1) artful_mercurial: not-affected (3.7.3-1ubuntu1) bionic_mercurial: not-affected (3.7.3-1ubuntu1) cosmic_mercurial: not-affected (3.7.3-1ubuntu1) devel_mercurial: not-affected (3.7.3-1ubuntu1)