6.8
CVSSv2

CVE-2008-2942

Published: 30/06/2008 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted malicious users to modify arbitrary files via ".." (dot dot) sequences in a patch file.

Vulnerable Product Search on Vulmon Subscribe to Product

mercurial mercurial 1.0.1

Vendor Advisories

Debian Bug report logs - #488628 mercurial: CVE-2008-2942 Insufficient input validation Package: mercurial; Maintainer for mercurial is Python Applications Packaging Team <python-apps-team@listsaliothdebianorg>; Source for mercurial is src:mercurial (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skol ...