8.8
CVE-2016-3068
- EPSS 5.41%
- Veröffentlicht 13.04.2016 16:59:16
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Fedoraproject ≫ Fedora Version 22
Fedoraproject ≫ Fedora Version 23
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Hpc Node Version 7.0
Redhat ≫ Enterprise Linux Hpc Node Eus Version 7.2
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.2
Redhat ≫ Enterprise Linux Server Eus Version 7.2
Redhat ≫ Enterprise Linux Workstation Version 7.0
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp4
Suse ≫ Linux Enterprise Software Development Kit Version 11 Update sp4
Suse ≫ Linux Enterprise Software Development Kit Version 12
Suse ≫ Linux Enterprise Software Development Kit Version 12 Update sp1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.41% | 0.917 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
https://security.gentoo.org/glsa/201612-19
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181505.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181542.html
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00016.html
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00017.html
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00018.html
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00043.html
http://rhn.redhat.com/errata/RHSA-2016-0706.html
http://www.debian.org/security/2016/dsa-3542
http://www.securityfocus.com/bid/85733
https://selenic.com/repo/hg-stable/rev/34d43cb85de8
https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.7.3_.282016-3-29.29