Candidate: CVE-2018-1000132 PublicDate: 2018-03-14 13:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000132 https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.5.1_.2F_4.5.2_.282018-03-06.29 https://www.mercurial-scm.org/repo/hg/rev/2ecb0fc535b1 (4.5.2) Description: Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1. Ubuntu-Description: It was discovered that Mercurial incorrectly handled access control. An attacker could possibly use this issue to execute arbitrary code. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=892964 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N [9.1 CRITICAL] Patches_mercurial: upstream_mercurial: needs-triage precise/esm_mercurial: DNE trusty_mercurial: released (2.8.2-1ubuntu1.4) trusty/esm_mercurial: released (2.8.2-1ubuntu1.4) xenial_mercurial: released (3.7.3-1ubuntu1.1) artful_mercurial: ignored (reached end-of-life) bionic_mercurial: not-affected (4.5.2-0ubuntu2) cosmic_mercurial: not-affected (4.5.2-0ubuntu2) devel_mercurial: not-affected (4.5.2-0ubuntu2)