CVE-2017-17458
published 2017-12-07CVE-2017-17458: In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a…
PriorityP352critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.33%
92.9th percentile
In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mercurial | < mercurial 4.4.1-1 (bookworm) | mercurial 4.4.1-1 (bookworm) |
| mercurial | mercurial | < 4.4.1 | 4.4.1 |
| mercurial | mercurial | >= 0 < 4.4.1-1 | 4.4.1-1 |
| mercurial | mercurial | >= 0 < 4.4.1-1 | 4.4.1-1 |
| mercurial | mercurial | >= 0 < 4.4.1-1 | 4.4.1-1 |
| mercurial | mercurial | >= 0 < 4.4.1-1 | 4.4.1-1 |
| mercurial | mercurial | >= 0 < 4.4.1 | 4.4.1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mercurial vulnerable to arbitrary code injection
ghsa·2022-05-13
CVE-2017-17458 [CRITICAL] CWE-78 Mercurial vulnerable to arbitrary code injection
Mercurial vulnerable to arbitrary code injection
In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a `.git/hooks/post-update` script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.
OSV
Mercurial vulnerable to arbitrary code injection
osv·2022-05-13
CVE-2017-17458 [CRITICAL] Mercurial vulnerable to arbitrary code injection
Mercurial vulnerable to arbitrary code injection
In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a `.git/hooks/post-update` script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.
OSV
CVE-2017-17458: In Mercurial before 4
osv·2017-12-07·CVSS 9.8
CVE-2017-17458 [CRITICAL] CVE-2017-17458: In Mercurial before 4
In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.
Red Hat
mercurial: arbitrary command execution in mercurial repo with a git submodule
vendor_redhat·2017-11-03·CVSS 9.8
CVE-2017-17458 [CRITICAL] mercurial: arbitrary command execution in mercurial repo with a git submodule
mercurial: arbitrary command execution in mercurial repo with a git submodule
In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.
It was found that mercurial was vulnerable to cross repositories modification. A specially crafted mercurial repository could trigger arbitrary commands on a client during commands such as clone or update.
Statement: This issue affects the versions of mercurial as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having Moderate security impact. A future upd
Debian
CVE-2017-17458: mercurial - In Mercurial before 4.4.1, it is possible that a specially malformed repository ...
vendor_debian·2017·CVSS 9.8
CVE-2017-17458 [CRITICAL] CVE-2017-17458: mercurial - In Mercurial before 4.4.1, it is possible that a specially malformed repository ...
In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.
Scope: local
bookworm: resolved (fixed in 4.4.1-1)
bullseye: resolved (fixed in 4.4.1-1)
forky: resolved (fixed in 4.4.1-1)
sid: resolved (fixed in 4.4.1-1)
trixie: resolved (fixed in 4.4.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-17458 mercurial: arbitrary command execution in mercurial repo with a git submodule [fedora-all]
bugzilla·2017-11-06·CVSS 9.8
CVE-2017-17458 [CRITICAL] CVE-2017-17458 mercurial: arbitrary command execution in mercurial repo with a git submodule [fedora-all]
CVE-2017-17458 mercurial: arbitrary command execution in mercurial repo with a git submodule [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1509868,1509869
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest th
Bugzilla
CVE-2017-17458 mercurial: arbitrary command execution in mercurial repo with a git submodule
bugzilla·2017-11-06·CVSS 9.8
CVE-2017-17458 [CRITICAL] CVE-2017-17458 mercurial: arbitrary command execution in mercurial repo with a git submodule
CVE-2017-17458 mercurial: arbitrary command execution in mercurial repo with a git submodule
A vulnerability in Mercurial's handling of subrepositories was reported on the Mercurial Project's *public* bug tracker.
The vulnerability results in arbitrary code execution during `hg clone` or `hg pull` + `hg update` if a well-crafted repository is cloned or pulled from. The vulnerability is known to occur with Git subrepositories. But it can also possibly occur with other subrepository types. The vulnerability likely impacts Mercurial versions released for the past several years.
Discussion:
External References:
https://bz.mercurial-scm.org/show_bug.cgi?id=5730
---
Created mercurial tracking bugs for this issue:
Affects: fedora-all [bug 1509869]
---
The fix consists of 2 distinct part
http://www.securityfocus.com/bid/102926https://bz.mercurial-scm.org/show_bug.cgi?id=5730https://confluence.atlassian.com/sourcetreekb/sourcetree-security-advisory-2018-01-24-942834324.htmlhttps://lists.debian.org/debian-lts-announce/2017/12/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00005.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00041.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00032.htmlhttps://www.mercurial-scm.org/pipermail/mercurial-devel/2017-November/107333.htmlhttps://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.4.1_.282017-11-07.29http://www.securityfocus.com/bid/102926https://bz.mercurial-scm.org/show_bug.cgi?id=5730https://confluence.atlassian.com/sourcetreekb/sourcetree-security-advisory-2018-01-24-942834324.htmlhttps://lists.debian.org/debian-lts-announce/2017/12/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00005.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00041.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00032.htmlhttps://www.mercurial-scm.org/pipermail/mercurial-devel/2017-November/107333.htmlhttps://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.4.1_.282017-11-07.29
2017-12-07
Published