CVE-2019-3902
published 2019-04-22CVE-2019-3902: A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside…
PriorityP429medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
1.41%
69.8th percentile
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | mercurial | < mercurial 4.9-1 (bookworm) | mercurial 4.9-1 (bookworm) |
| mercurial | mercurial | < 4.9 | 4.9 |
| mercurial | mercurial | >= 0 < 4.9-1 | 4.9-1 |
| mercurial | mercurial | >= 0 < 4.9-1 | 4.9-1 |
| mercurial | mercurial | >= 0 < 4.9-1 | 4.9-1 |
| mercurial | mercurial | >= 0 < 4.9-1 | 4.9-1 |
| mercurial | mercurial | >= 0 < 4.9 | 4.9 |
| mercurial | mercurial | >= 0 < 4.5.3-1ubuntu2.2 | 4.5.3-1ubuntu2.2 |
| mercurial | mercurial | >= 0 < 2.8.2-1ubuntu1.4+esm1 | 2.8.2-1ubuntu1.4+esm1 |
| mercurial | mercurial | >= 0 < 3.7.3-1ubuntu1.2+esm2 | 3.7.3-1ubuntu1.2+esm2 |
| redhat | enterprise_linux | — | — |
| the_mercurial_project | mercurial | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv9.1CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Mercurial vulnerabilities
vendor_ubuntu·2021-10-04·CVSS 9.1
CVE-2019-3902 [CRITICAL] Mercurial vulnerabilities
Title: Mercurial vulnerabilities
Summary: Several security issues were fixed in Mercurial.
It was discovered that Mercurial mishandled symlinks in subrepositories. An
attacker could use this issue to write arbitrary files to the
target’s filesystem. (CVE-2019-3902)
It was discovered that Mercurial incorrectly handled certain manifest files.
An attacker could use this issue to cause a denial of service and possibly
execute arbitrary code. (CVE-2018-17983)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Mercurial vulnerabilities
vendor_ubuntu·2021-03-16·CVSS 9.1
CVE-2019-3902 [CRITICAL] Mercurial vulnerabilities
Title: Mercurial vulnerabilities
Summary: Mercurial could be made to overwrite files.
USN-5102-1 fixed vulnerabilities in Mercurial. This update provides the
corresponding updates for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Mercurial mishandled symlinks in subrepositories. An
attacker could use this issue to write arbitrary files to the
target’s filesystem. (CVE-2019-3902)
It was discovered that Mercurial incorrectly handled certain manifest files.
An attacker could use this issue to cause a denial of service and possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 ESM. (CVE-2018-17983)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Mercurial vulnerability
vendor_ubuntu·2019-08-06
CVE-2019-3902 Mercurial vulnerability
Title: Mercurial vulnerability
Summary: Mercurial could be made to overwrite files.
It was discovered that Mercurial mishandled symlinks in subrepositories. An
attacker could use this vulnerability to write arbitrary files to the
target's filesystem.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
mercurial: Path-checking logic bypass via symlinks and subrepositories
vendor_redhat·2019-03-13·CVSS 5.1
CVE-2019-3902 [MEDIUM] CWE-22 mercurial: Path-checking logic bypass via symlinks and subrepositories
mercurial: Path-checking logic bypass via symlinks and subrepositories
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
Starting with version 1.5.3, Mercurial allows environment variable expansion on path names for sub repositories when creating it or cloning a parent repository, but it doesn't validate whether the final path name outside the repository root directory. An attacker can leverage this weakness using a combination of symbolic links and environment variables to craft a tampered repository, leading Mercurial to write files outside the repository as long the destination location is empty.
Statement: This issue affects the versions of mercurial as shipped
Debian
CVE-2019-3902: mercurial - A flaw was found in Mercurial before 4.9. It was possible to use symlinks and su...
vendor_debian·2019·CVSS 5.1
CVE-2019-3902 [MEDIUM] CVE-2019-3902: mercurial - A flaw was found in Mercurial before 4.9. It was possible to use symlinks and su...
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
Scope: local
bookworm: resolved (fixed in 4.9-1)
bullseye: resolved (fixed in 4.9-1)
forky: resolved (fixed in 4.9-1)
sid: resolved (fixed in 4.9-1)
trixie: resolved (fixed in 4.9-1)
OSV
Mercurial Path Traversal/Link Following vulnerability
osv·2022-02-15
CVE-2019-3902 [MEDIUM] Mercurial Path Traversal/Link Following vulnerability
Mercurial Path Traversal/Link Following vulnerability
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
GHSA
Mercurial Path Traversal/Link Following vulnerability
ghsa·2022-02-15
CVE-2019-3902 [MEDIUM] CWE-22 Mercurial Path Traversal/Link Following vulnerability
Mercurial Path Traversal/Link Following vulnerability
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
OSV
mercurial vulnerabilities
osv·2021-10-04·CVSS 9.1
CVE-2019-3902 [CRITICAL] mercurial vulnerabilities
mercurial vulnerabilities
It was discovered that Mercurial mishandled symlinks in subrepositories. An
attacker could use this issue to write arbitrary files to the
target’s filesystem. (CVE-2019-3902)
It was discovered that Mercurial incorrectly handled certain manifest files.
An attacker could use this issue to cause a denial of service and possibly
execute arbitrary code. (CVE-2018-17983)
OSV
mercurial vulnerabilities
osv·2021-03-16·CVSS 9.1
CVE-2019-3902 [CRITICAL] mercurial vulnerabilities
mercurial vulnerabilities
USN-5102-1 fixed vulnerabilities in Mercurial. This update provides the
corresponding updates for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Mercurial mishandled symlinks in subrepositories. An
attacker could use this issue to write arbitrary files to the
target’s filesystem. (CVE-2019-3902)
It was discovered that Mercurial incorrectly handled certain manifest files.
An attacker could use this issue to cause a denial of service and possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 ESM. (CVE-2018-17983)
OSV
CVE-2019-3902: A flaw was found in Mercurial before 4
osv·2019-04-22·CVSS 5.9
CVE-2019-3902 [MEDIUM] CVE-2019-3902: A flaw was found in Mercurial before 4
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3902 mercurial: Path-checking logic bypass via symlinks and subrepositories
bugzilla·2019-04-04·CVSS 5.1
CVE-2019-3902 [MEDIUM] CVE-2019-3902 mercurial: Path-checking logic bypass via symlinks and subrepositories
CVE-2019-3902 mercurial: Path-checking logic bypass via symlinks and subrepositories
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
References:
https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.9_.282019-02-01.29
Discussion:
Created mercurial tracking bugs for this issue:
Affects: fedora-all [bug 1696026]
---
Statement:
This issue affects the versions of mercurial as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having a security impact of Moderate. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/class
Bugzilla
CVE-2019-3902 mercurial: Path-checking logic bypass via symlinks and subrepositories [fedora-all]
bugzilla·2019-04-04·CVSS 5.1
CVE-2019-3902 [MEDIUM] CVE-2019-3902 mercurial: Path-checking logic bypass via symlinks and subrepositories [fedora-all]
CVE-2019-3902 mercurial: Path-checking logic bypass via symlinks and subrepositories [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3902https://lists.debian.org/debian-lts-announce/2019/04/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00032.htmlhttps://usn.ubuntu.com/4086-1/https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.9_.282019-02-01.29https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3902https://lists.debian.org/debian-lts-announce/2019/04/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00032.htmlhttps://usn.ubuntu.com/4086-1/https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.9_.282019-02-01.29
2019-04-22
Published