CVE-2016-3105
published 2016-05-09CVE-2016-3105: The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.
PriorityP346high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.66%
84.0th percentile
The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | mercurial | < mercurial 3.8.1-1 (bookworm) | mercurial 3.8.1-1 (bookworm) |
| mercurial | mercurial | <= 3.7.3 | — |
| mercurial | mercurial | >= 0 < 3.8.1-1 | 3.8.1-1 |
| mercurial | mercurial | >= 0 < 3.8.1-1 | 3.8.1-1 |
| mercurial | mercurial | >= 0 < 3.8.1-1 | 3.8.1-1 |
| mercurial | mercurial | >= 0 < 3.8.1-1 | 3.8.1-1 |
| mercurial | mercurial | >= 0 < 3.8 | 3.8 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mercurial: arbitrary code execution when converting git repos
vendor_redhat·2016-04-06·CVSS 8.8
CVE-2016-3105 [HIGH] CWE-77 mercurial: arbitrary code execution when converting git repos
mercurial: arbitrary code execution when converting git repos
The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.
It was discovered that the Mercurial convert extension invoked Git in a way that could cause Git to interpret local repository name as remote repository URL. A Git repository with a specially crafted name could cause Mercurial to execute arbitrary code when the Git repository was converted to a Mercurial repository.
Package: mercurial (Red Hat Enterprise Linux 6) - Will not fix
Package: mercurial (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-3105: mercurial - The convert extension in Mercurial before 3.8 might allow context-dependent atta...
vendor_debian·2016·CVSS 8.8
CVE-2016-3105 [HIGH] CVE-2016-3105: mercurial - The convert extension in Mercurial before 3.8 might allow context-dependent atta...
The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.
Scope: local
bookworm: resolved (fixed in 3.8.1-1)
bullseye: resolved (fixed in 3.8.1-1)
forky: resolved (fixed in 3.8.1-1)
sid: resolved (fixed in 3.8.1-1)
trixie: resolved (fixed in 3.8.1-1)
GHSA
Mercurial vulnerable to arbitrary code execution when converting Git repos
ghsa·2022-05-17
CVE-2016-3105 [HIGH] CWE-284 Mercurial vulnerable to arbitrary code execution when converting Git repos
Mercurial vulnerable to arbitrary code execution when converting Git repos
The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.
OSV
Mercurial vulnerable to arbitrary code execution when converting Git repos
osv·2022-05-17
CVE-2016-3105 [HIGH] Mercurial vulnerable to arbitrary code execution when converting Git repos
Mercurial vulnerable to arbitrary code execution when converting Git repos
The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.
OSV
CVE-2016-3105: The convert extension in Mercurial before 3
osv·2016-05-09·CVSS 8.8
CVE-2016-3105 [HIGH] CVE-2016-3105: The convert extension in Mercurial before 3
The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3105 mercurial: arbitrary code execution when converting git repos
bugzilla·2016-05-04·CVSS 9.8
CVE-2016-3105 [CRITICAL] CVE-2016-3105 mercurial: arbitrary code execution when converting git repos
CVE-2016-3105 mercurial: arbitrary code execution when converting git repos
A possible arbitrary code execution when converting Git repos was found in Mercirual. Mercurial prior to 3.8 allowed arbitrary code execution when using the convert extension on Git repos with hostile names. This could affect automated code conversion services that allow arbitrary repository names. This is a further side-effect of Git CVE-2015-7545.
External Reference:
https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.8_.2F_3.8.1_.282016-5-1.29
Upstream fix:
https://selenic.com/hg/rev/a56296f55a5e
Discussion:
Created mercurial tracking bugs for this issue:
Affects: fedora-all [bug 1332946]
Bugzilla
CVE-2016-3105 mercurial: arbitrary code execution when converting git repos [fedora-all]
bugzilla·2016-05-04·CVSS 8.8
CVE-2016-3105 [HIGH] CVE-2016-3105 mercurial: arbitrary code execution when converting git repos [fedora-all]
CVE-2016-3105 mercurial: arbitrary code execution when converting git repos [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
http://lists.opensuse.org/opensuse-updates/2016-05/msg00082.htmlhttp://www.debian.org/security/2016/dsa-3570http://www.securityfocus.com/bid/90536http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.533255https://security.gentoo.org/glsa/201612-19https://selenic.com/hg/rev/a56296f55a5ehttps://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.8_.2F_3.8.1_.282016-5-1.29http://lists.opensuse.org/opensuse-updates/2016-05/msg00082.htmlhttp://www.debian.org/security/2016/dsa-3570http://www.securityfocus.com/bid/90536http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.533255https://security.gentoo.org/glsa/201612-19https://selenic.com/hg/rev/a56296f55a5ehttps://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.8_.2F_3.8.1_.282016-5-1.29
2016-05-09
Published