Candidate: CVE-2016-3630 PublicDate: 2016-04-13 16:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3630 https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.7.3_.282016-3-29.29 https://selenic.com/repo/hg-stable/rev/b6ed2505d6cf (1/2) https://selenic.com/repo/hg-stable/rev/b9714d958e89 (2/2) Description: The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records. Ubuntu-Description: It was discovered that Mercurial incorrectly handled delta decoding. An attacker could possibly use this issue to execute arbitrary code. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=819504 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_mercurial: upstream_mercurial: released (3.7.3-1) precise_mercurial: ignored (reached end-of-life) precise/esm_mercurial: DNE (precise was needed) trusty_mercurial: released (2.8.2-1ubuntu1.4) trusty/esm_mercurial: released (2.8.2-1ubuntu1.4) vivid/stable-phone-overlay_mercurial: DNE vivid/ubuntu-core_mercurial: DNE wily_mercurial: ignored (reached end-of-life) xenial_mercurial: not-affected (3.7.3-1ubuntu1) yakkety_mercurial: not-affected (3.7.3-1ubuntu1) zesty_mercurial: not-affected (3.7.3-1ubuntu1) artful_mercurial: not-affected (3.7.3-1ubuntu1) bionic_mercurial: not-affected (3.7.3-1ubuntu1) cosmic_mercurial: not-affected (3.7.3-1ubuntu1) devel_mercurial: not-affected (3.7.3-1ubuntu1)