CVE-2018-13348

The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mercurial:mercurial:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:46

Type Values Removed Values Added
References () https://lists.debian.org/debian-lts-announce/2020/07/msg00032.html - () https://lists.debian.org/debian-lts-announce/2020/07/msg00032.html -
References () https://www.mercurial-scm.org/repo/hg/rev/90a274965de7 - Vendor Advisory, Patch () https://www.mercurial-scm.org/repo/hg/rev/90a274965de7 - Patch, Vendor Advisory
References () https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.6.1_.282018-06-06.29 - Vendor Advisory () https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.6.1_.282018-06-06.29 - Vendor Advisory

Information

Published : 2018-07-06 00:29

Updated : 2024-11-21 03:46


NVD link : CVE-2018-13348

Mitre link : CVE-2018-13348

CVE.ORG link : CVE-2018-13348


JSON object : View

Products Affected

mercurial

  • mercurial
CWE
CWE-20

Improper Input Validation