8.8
CVE-2016-3069
- EPSS 4.95%
- Veröffentlicht 13.04.2016 16:59:17
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp4
Suse ≫ Linux Enterprise Software Development Kit Version 11 Update sp4
Suse ≫ Linux Enterprise Software Development Kit Version 12
Suse ≫ Linux Enterprise Software Development Kit Version 12 Update sp1
Fedoraproject ≫ Fedora Version 22
Fedoraproject ≫ Fedora Version 23
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Hpc Node Version 7.0
Redhat ≫ Enterprise Linux Hpc Node Eus Version 7.2
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.2
Redhat ≫ Enterprise Linux Server Eus Version 7.2
Redhat ≫ Enterprise Linux Workstation Version 7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.95% | 0.911 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
https://security.gentoo.org/glsa/201612-19
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181505.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181542.html
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00016.html
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00017.html
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00018.html
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00043.html
http://rhn.redhat.com/errata/RHSA-2016-0706.html
http://www.debian.org/security/2016/dsa-3542
https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.7.3_.282016-3-29.29
https://selenic.com/repo/hg-stable/rev/197eed39e3d5
https://selenic.com/repo/hg-stable/rev/80cac1de6aea
https://selenic.com/repo/hg-stable/rev/ae279d4a19e9
https://selenic.com/repo/hg-stable/rev/b732e7f2aba4
https://selenic.com/repo/hg-stable/rev/cdda7b96afff