CVE-2016-3068
published 2016-04-13CVE-2016-3068: Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
PriorityP351high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
5.41%
91.8th percentile
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mercurial | < mercurial 3.7.3-1 (bookworm) | mercurial 3.7.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mercurial | mercurial | <= 3.7.2 | — |
| mercurial | mercurial | >= 0 < 3.7.3-1 | 3.7.3-1 |
| mercurial | mercurial | >= 0 < 3.7.3-1 | 3.7.3-1 |
| mercurial | mercurial | >= 0 < 3.7.3-1 | 3.7.3-1 |
| mercurial | mercurial | >= 0 < 3.7.3-1 | 3.7.3-1 |
| mercurial | mercurial | >= 0 < 3.7.3 | 3.7.3 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_debuginfo | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mercurial: command injection via git subrepository urls
vendor_redhat·2016-03-29·CVSS 8.8
CVE-2016-3068 [HIGH] CWE-77 mercurial: command injection via git subrepository urls
mercurial: command injection via git subrepository urls
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
It was discovered that Mercurial failed to properly check Git sub-repository URLs. A Mercurial repository that includes a Git sub-repository with a specially crafted URL could cause Mercurial to execute arbitrary code.
Package: mercurial (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2016-3068: mercurial - Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a c...
vendor_debian·2016·CVSS 8.8
CVE-2016-3068 [HIGH] CVE-2016-3068: mercurial - Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a c...
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
Scope: local
bookworm: resolved (fixed in 3.7.3-1)
bullseye: resolved (fixed in 3.7.3-1)
forky: resolved (fixed in 3.7.3-1)
sid: resolved (fixed in 3.7.3-1)
trixie: resolved (fixed in 3.7.3-1)
GHSA
Mercurial arbitrary code execution via a crafted git ext:: URL
ghsa·2022-05-14
CVE-2016-3068 [HIGH] CWE-20 Mercurial arbitrary code execution via a crafted git ext:: URL
Mercurial arbitrary code execution via a crafted git ext:: URL
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
OSV
Mercurial arbitrary code execution via a crafted git ext:: URL
osv·2022-05-14
CVE-2016-3068 [HIGH] Mercurial arbitrary code execution via a crafted git ext:: URL
Mercurial arbitrary code execution via a crafted git ext:: URL
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
OSV
CVE-2016-3068: Mercurial before 3
osv·2016-04-13·CVSS 8.8
CVE-2016-3068 [HIGH] CVE-2016-3068: Mercurial before 3
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3068 mercurial: Git ext:: URLs specified in Mercurial subrepositories allows RCE [fedora-all]
bugzilla·2016-04-04·CVSS 8.8
CVE-2016-3068 [HIGH] CVE-2016-3068 mercurial: Git ext:: URLs specified in Mercurial subrepositories allows RCE [fedora-all]
CVE-2016-3068 mercurial: Git ext:: URLs specified in Mercurial subrepositories allows RCE [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2016-3630 CVE-2016-3068 CVE-2016-3069 mercurial: various flaws [fedora-all]
bugzilla·2016-03-30·CVSS 8.8
CVE-2016-3630 [HIGH] CVE-2016-3630 CVE-2016-3068 CVE-2016-3069 mercurial: various flaws [fedora-all]
CVE-2016-3630 CVE-2016-3068 CVE-2016-3069 mercurial: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
Bugzilla
CVE-2016-3068 mercurial: command injection via git subrepository urls
bugzilla·2016-03-21·CVSS 9.8
CVE-2016-3068 [CRITICAL] CVE-2016-3068 mercurial: command injection via git subrepository urls
CVE-2016-3068 mercurial: command injection via git subrepository urls
It was reported that in mercurial, there is similar vulnerability as CVE-2015-7545 in git. Git's git-remote-ext remote helper provides an ext:: URL scheme that allows running arbitrary shell commands. Mercurial allows specifying git repositories as subrepositories. Git ext:: URLs can be specified as Mercurial subrepositories allowing arbitrary shell commands to be run on `hg clone ...`.
Discussion:
Acknowledgments:
Name: Blake Burkhart
---
*** Bug 1322266 has been marked as a duplicate of this bug. ***
---
External references:
https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.7.3_.282016-3-29.29
Upstream fix:
https://selenic.com/repo/hg-stable/rev/34d43cb85de8
---
Created mercurial tracking bugs for th
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181505.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-April/181542.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00043.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0706.htmlhttp://www.debian.org/security/2016/dsa-3542http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/bid/85733https://security.gentoo.org/glsa/201612-19https://selenic.com/repo/hg-stable/rev/34d43cb85de8https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.7.3_.282016-3-29.29http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181505.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-April/181542.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00043.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0706.htmlhttp://www.debian.org/security/2016/dsa-3542http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/bid/85733https://security.gentoo.org/glsa/201612-19https://selenic.com/repo/hg-stable/rev/34d43cb85de8https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.7.3_.282016-3-29.29
2016-04-13
Published