CVE-2018-17983Out-of-bounds Read in Mercurial

CWE-125Out-of-bounds Read13 documents8 sources
Severity
9.1CRITICALNVD
EPSS
0.4%
top 36.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 4
Latest updateMay 14

Description

cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages5 packages

debiandebian/mercurial< mercurial 4.7.2-1 (bookworm)
NVDmercurial/mercurial< 4.7.2
PyPImercurial/mercurial< 4.7.2
Debianmercurial/mercurial< 4.7.2-1+3
Ubuntumercurial/mercurial< 4.5.3-1ubuntu2.2+2

Patches

🔴Vulnerability Details

6
GHSA
Mercurial Out-of-bounds Read vulnerability2022-05-14
OSV
Mercurial Out-of-bounds Read vulnerability2022-05-14
OSV
mercurial vulnerabilities2021-10-04
OSV
mercurial vulnerabilities2021-03-16
CVEList
CVE-2018-17983: cext/manifest2018-10-04

📋Vendor Advisories

4
Ubuntu
Mercurial vulnerabilities2021-10-04
Ubuntu
Mercurial vulnerabilities2021-03-16
Red Hat
mercurial: Out-of-bounds read in cext/manifest.c2018-10-01
Debian
CVE-2018-17983: mercurial - cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsi...2018

💬Community

2
Bugzilla
CVE-2018-17983 mercurial: Out-of-bounds read in cext/manifest.c [fedora-all]2018-10-09
Bugzilla
CVE-2018-17983 mercurial: Out-of-bounds read in cext/manifest.c2018-10-09