CVE-2016-3630
published 2016-04-13CVE-2016-3630: The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to…
PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.83%
91.0th percentile
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mercurial | < mercurial 3.7.3-1 (bookworm) | mercurial 3.7.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mercurial | mercurial | <= 3.7.2 | — |
| mercurial | mercurial | >= 0 < 3.7.3-1 | 3.7.3-1 |
| mercurial | mercurial | >= 0 < 3.7.3-1 | 3.7.3-1 |
| mercurial | mercurial | >= 0 < 3.7.3-1 | 3.7.3-1 |
| mercurial | mercurial | >= 0 < 3.7.3-1 | 3.7.3-1 |
| mercurial | mercurial | >= 0 < 3.7.3 | 3.7.3 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_debuginfo | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mercurial arbitrary code execution vulnerability
osv·2022-05-14
CVE-2016-3630 [HIGH] Mercurial arbitrary code execution vulnerability
Mercurial arbitrary code execution vulnerability
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
GHSA
Mercurial arbitrary code execution vulnerability
ghsa·2022-05-14
CVE-2016-3630 [HIGH] Mercurial arbitrary code execution vulnerability
Mercurial arbitrary code execution vulnerability
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
OSV
CVE-2016-3630: The binary delta decoder in Mercurial before 3
osv·2016-04-13·CVSS 8.8
CVE-2016-3630 [HIGH] CVE-2016-3630: The binary delta decoder in Mercurial before 3
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
Red Hat
mercurial: remote code execution in binary delta decoding
vendor_redhat·2016-03-29·CVSS 8.8
CVE-2016-3630 [HIGH] CWE-119 mercurial: remote code execution in binary delta decoding
mercurial: remote code execution in binary delta decoding
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
Package: mercurial (Red Hat Enterprise Linux 6) - Not affected
Package: mercurial (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-3630: mercurial - The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to ex...
vendor_debian·2016·CVSS 8.8
CVE-2016-3630 [HIGH] CVE-2016-3630: mercurial - The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to ex...
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
Scope: local
bookworm: resolved (fixed in 3.7.3-1)
bullseye: resolved (fixed in 3.7.3-1)
forky: resolved (fixed in 3.7.3-1)
sid: resolved (fixed in 3.7.3-1)
trixie: resolved (fixed in 3.7.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3630 mercurial: remote code execution in binary delta decoding
bugzilla·2016-03-30·CVSS 8.8
CVE-2016-3630 [HIGH] CVE-2016-3630 mercurial: remote code execution in binary delta decoding
CVE-2016-3630 mercurial: remote code execution in binary delta decoding
Mercurial prior to 3.7.3 contained two bounds-checking errors in its binary delta decoder that may be exploitable via clone, push, or pull.
External references:
https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.7.3_.282016-3-29.29
Upstream fixes:
https://selenic.com/repo/hg-stable/rev/b6ed2505d6cf
https://selenic.com/repo/hg-stable/rev/b9714d958e89
Discussion:
Created mercurial tracking bugs for this issue:
Affects: fedora-all [bug 1322268]
---
mercurial-3.5.2-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
---
mercurial-3.5.2-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please mak
Bugzilla
CVE-2016-3630 CVE-2016-3068 CVE-2016-3069 mercurial: various flaws [fedora-all]
bugzilla·2016-03-30·CVSS 8.8
CVE-2016-3630 [HIGH] CVE-2016-3630 CVE-2016-3068 CVE-2016-3069 mercurial: various flaws [fedora-all]
CVE-2016-3630 CVE-2016-3068 CVE-2016-3069 mercurial: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181505.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-April/181542.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00043.htmlhttp://www.debian.org/security/2016/dsa-3542http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttps://security.gentoo.org/glsa/201612-19https://selenic.com/repo/hg-stable/rev/b6ed2505d6cfhttps://selenic.com/repo/hg-stable/rev/b9714d958e89https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.7.3_.282016-3-29.29http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181505.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-April/181542.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00043.htmlhttp://www.debian.org/security/2016/dsa-3542http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttps://security.gentoo.org/glsa/201612-19https://selenic.com/repo/hg-stable/rev/b6ed2505d6cfhttps://selenic.com/repo/hg-stable/rev/b9714d958e89https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.7.3_.282016-3-29.29
2016-04-13
Published