Bug 1053344 - (CVE-2017-1000115) VUL-0: CVE-2017-1000115: mercurial: path traversal via symlink
(CVE-2017-1000115)
VUL-0: CVE-2017-1000115: mercurial: path traversal via symlink
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/190229/
CVSSv3:RedHat:CVE-2017-1000115:5.4:(A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-08-11 05:53 UTC by Marcus Meissner
Modified: 2017-10-25 16:59 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-08-11 05:53:35 UTC
rh#1480330

The symlink auditor is sometimes cached too long, and can be confused into allowing write access to outside the repo.


https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.3_.282017-08-10.29
Comment 1 Marcus Meissner 2017-08-11 05:56:19 UTC
Please include into current submissions.
Comment 2 Takashi Iwai 2017-08-11 09:42:18 UTC
4.2.3 was submitted to TW and Leap 42.3, which should include this fix as well.
Comment 3 Takashi Iwai 2017-08-12 21:18:12 UTC
The fix for Leap 42.2:Update was submitted via SR#516580.
The fix for SLE12:Update was submitted via SR#137790.
The fix for SLE11-SP3:Update was submitted via SR#137791.
Comment 4 Bernhard Wiedemann 2017-08-12 22:01:00 UTC
This is an autogenerated message for OBS integration:
This bug (1053344) was mentioned in
https://build.opensuse.org/request/show/516580 42.2 / mercurial
Comment 6 Swamp Workflow Management 2017-08-16 22:10:50 UTC
openSUSE-SU-2017:2187-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1052696,1053344
CVE References: CVE-2017-1000115,CVE-2017-1000116
Sources used:
openSUSE Leap 42.3 (src):    mercurial-4.2.3-4.1
openSUSE Leap 42.2 (src):    mercurial-3.8.3-2.8.1
Comment 7 Swamp Workflow Management 2017-08-24 22:07:22 UTC
SUSE-SU-2017:2250-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1052696,1053344
CVE References: CVE-2017-1000115,CVE-2017-1000116
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    mercurial-2.3.2-0.18.3.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    mercurial-2.3.2-0.18.3.1
Comment 8 Swamp Workflow Management 2017-08-24 22:07:54 UTC
SUSE-SU-2017:2251-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1052696,1053344
CVE References: CVE-2017-1000115,CVE-2017-1000116
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    mercurial-2.8.2-15.3.1
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    mercurial-2.8.2-15.3.1
Comment 9 Marcus Meissner 2017-10-25 16:59:27 UTC
released