Bugzilla – Bug 1043063
VUL-0: CVE-2017-9462: mercurial: before version 4.1.3, "hg serve --stdio" allows remote authenticated users to execute arbitrary code
Last modified: 2017-10-25 19:08:39 UTC
CVE-2017-9462 In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-9462 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=861243 http://www.cvedetails.com/cve/CVE-2017-9462/ https://www.mercurial-scm.org/repo/hg/rev/77eaf9539499 https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.1.3_.282017-4-18.29
The fix is submitted to SLE11-SP3, SLE12, and openSUSE Leap 42.2. Leap 42.3 and TW have the newer version that already contains the fix.
Is the fix for SUSE:SLE-11:Update still necessary? Otherwise all fixes have been done.
This is an autogenerated message for OBS integration: This bug (1043063) was mentioned in https://build.opensuse.org/request/show/501772 42.2 / mercurial
Possible regression bug 1043502
This is an autogenerated message for OBS integration: This bug (1043063) was mentioned in https://build.opensuse.org/request/show/502508 42.2 / mercurial
Reassigned back to security team.
SUSE-SU-2017:1558-1: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1043063,1043502 CVE References: CVE-2017-9462 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): mercurial-2.3.2-0.17.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): mercurial-2.3.2-0.17.1
openSUSE-SU-2017:1572-1: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1043063,1043502 CVE References: CVE-2017-9462 Sources used: openSUSE Leap 42.2 (src): mercurial-3.8.3-2.5.1
SUSE-SU-2017:1606-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1043063 CVE References: CVE-2017-9462 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP2 (src): mercurial-2.8.2-14.1
released