Bug 1459482 (CVE-2017-9462) - CVE-2017-9462 mercurial: Python debugger accessible to authorized users
Summary: CVE-2017-9462 mercurial: Python debugger accessible to authorized users
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2017-9462
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1459485 1460964 1460965 1460966 1460967
Blocks: 1459488
TreeView+ depends on / blocked
 
Reported: 2017-06-07 09:23 UTC by Adam Mariš
Modified: 2021-02-04 00:46 UTC (History)
3 users (show)

Fixed In Version: mercurial 4.1.3
Clone Of:
Environment:
Last Closed: 2019-06-08 03:14:50 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:1576 0 normal SHIPPED_LIVE Important: mercurial security update 2017-06-27 11:30:36 UTC

Description Adam Mariš 2017-06-07 09:23:41 UTC
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.

Reference:

https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.1.3_.282017-4-18.29

Upstream patch:

https://www.mercurial-scm.org/repo/hg/rev/77eaf9539499

Comment 1 Adam Mariš 2017-06-07 09:24:10 UTC
Created mercurial tracking bugs for this issue:

Affects: fedora-all [bug 1459485]

Comment 9 errata-xmlrpc 2017-06-27 07:31:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6
  Red Hat Enterprise Linux 7

Via RHSA-2017:1576 https://access.redhat.com/errata/RHSA-2017:1576


Note You need to log in before you can comment on or make changes to this bug.