Bug 1043063 - (CVE-2017-9462) VUL-0: CVE-2017-9462: mercurial: before version 4.1.3, "hg serve --stdio" allows remote authenticated users to execute arbitrary code
(CVE-2017-9462)
VUL-0: CVE-2017-9462: mercurial: before version 4.1.3, "hg serve --stdio" al...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/186373/
CVSSv3:SUSE:CVE-2017-9462:9.0:(AV:N/A...
:
Depends on: 1043502
Blocks:
  Show dependency treegraph
 
Reported: 2017-06-07 07:29 UTC by Victor Pereira
Modified: 2017-10-25 19:08 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2017-06-07 07:29:07 UTC
CVE-2017-9462

In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users
to launch the Python debugger, and consequently execute arbitrary code, by using
--debugger as a repository name.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-9462
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=861243
http://www.cvedetails.com/cve/CVE-2017-9462/
https://www.mercurial-scm.org/repo/hg/rev/77eaf9539499
https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.1.3_.282017-4-18.29
Comment 1 Takashi Iwai 2017-06-07 14:35:37 UTC
The fix is submitted to SLE11-SP3, SLE12, and openSUSE Leap 42.2.
Leap 42.3 and TW have the newer version that already contains the fix.
Comment 2 Takashi Iwai 2017-06-07 15:07:06 UTC
Is the fix for SUSE:SLE-11:Update still necessary?
Otherwise all fixes have been done.
Comment 3 Bernhard Wiedemann 2017-06-07 16:01:12 UTC
This is an autogenerated message for OBS integration:
This bug (1043063) was mentioned in
https://build.opensuse.org/request/show/501772 42.2 / mercurial
Comment 5 Andreas Stieger 2017-06-09 05:12:39 UTC
Possible regression bug 1043502
Comment 6 Bernhard Wiedemann 2017-06-09 10:01:05 UTC
This is an autogenerated message for OBS integration:
This bug (1043063) was mentioned in
https://build.opensuse.org/request/show/502508 42.2 / mercurial
Comment 8 Takashi Iwai 2017-06-13 06:52:46 UTC
Reassigned back to security team.
Comment 9 Swamp Workflow Management 2017-06-13 19:11:03 UTC
SUSE-SU-2017:1558-1: An update that solves one vulnerability and has one errata is now available.

Category: security (important)
Bug References: 1043063,1043502
CVE References: CVE-2017-9462
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    mercurial-2.3.2-0.17.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    mercurial-2.3.2-0.17.1
Comment 10 Swamp Workflow Management 2017-06-15 16:11:18 UTC
openSUSE-SU-2017:1572-1: An update that solves one vulnerability and has one errata is now available.

Category: security (important)
Bug References: 1043063,1043502
CVE References: CVE-2017-9462
Sources used:
openSUSE Leap 42.2 (src):    mercurial-3.8.3-2.5.1
Comment 11 Swamp Workflow Management 2017-06-19 13:15:02 UTC
SUSE-SU-2017:1606-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1043063
CVE References: CVE-2017-9462
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    mercurial-2.8.2-14.1
Comment 12 Marcus Meissner 2017-10-25 19:08:39 UTC
released