Red Hat Bugzilla – Bug 1594087
CVE-2018-13347 mercurial: Buffer underflow in mpatch.c:mpatch_apply()
Last modified: 2018-09-30 18:13:26 EDT
Mercurial before version 4.6.1 is vulnerable to a buffer underflow in mpatch.c:mpatch_apply(). Upstream Changelog: https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.6.1_.282018-06-06.29 Upstream Patch: https://www.mercurial-scm.org/repo/hg/rev/1acfc35d478c
Created mercurial tracking bugs for this issue: Affects: fedora-all [bug 1594088]
This is related to CVE-2018-13346: this issue is writing before the output buffer, where the other reads past the end of input. In mercurial 2.6.2, it is present in the apply() function.