Description
Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.
CVSS vector
AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4 Affected Packages4 packages
🔴Vulnerability Details
3OSVMercurial Directory traversal vulnerability↗2022-05-01 ▶ GHSAMercurial Directory traversal vulnerability↗2022-05-01 ▶ OSVCVE-2008-2942: Directory traversal vulnerability in patch↗2008-06-30 ▶ 📋Vendor Advisories
2Red Hatmercurial: insufficient input validationn allowing file renames out of repository↗2008-06-25 ▶ DebianCVE-2008-2942: mercurial - Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-ass...↗2008 ▶ 💬Community
2BugzillaCVE-2008-2942 CVE-2008-4297 mercurial: multiple security issues [Fedora 8]↗2008-09-29 ▶ BugzillaCVE-2008-2942 mercurial: insufficient input validationn allowing file renames out of repository↗2008-07-01 ▶