cbcvebase.
CVE-2017-1000116
published 2017-10-05

CVE-2017-1000116: Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalbazaar<= 2.7.0
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianbreezy< breezy 3.0.0~bzr6772-1 (bookworm)breezy 3.0.0~bzr6772-1 (bookworm)
debianbzr< breezy 3.0.0~bzr6772-1 (bookworm)breezy 3.0.0~bzr6772-1 (bookworm)
debianbzr0 – 2.7.0
debiandebian_linux
debiandebian_linux
debiandulwich< dulwich 0.18.5-1 (bookworm)dulwich 0.18.5-1 (bookworm)
debianfossil< fossil 1:2.4-1 (bookworm)fossil 1:2.4-1 (bookworm)
debiangit-annex< git-annex 6.20170818-1 (bookworm)git-annex 6.20170818-1 (bookworm)
debianmercurial< mercurial 4.3.1-1 (bookworm)mercurial 4.3.1-1 (bookworm)
dulwich_projectdulwich<= 0.18.4
dulwich_projectdulwich>= 0 < 0.18.5-10.18.5-1
dulwich_projectdulwich>= 0 < 0.18.5-10.18.5-1
dulwich_projectdulwich>= 0 < 0.18.5-10.18.5-1
dulwich_projectdulwich>= 0 < 0.18.5-10.18.5-1
dulwich_projectdulwich>= 0 < 0.18.50.18.5
fossil-scmfossil>= 0 < 1:2.4-11:2.4-1
fossil-scmfossil>= 0 < 1:2.4-11:2.4-1
fossil-scmfossil>= 0 < 1:2.4-11:2.4-1
fossil_scmfossil< 2.42.4
git-annex_projectgit-annex<= 6.20170520
git-annex_projectgit-annex>= 0 < 6.20170818-16.20170818-1

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa9.8CRITICAL
osv9.8CRITICAL