Vulnerability Name:

CVE-2018-17983 (CCN-150936)

Assigned:2018-10-01
Published:2018-10-01
Updated:2018-12-13
Summary:cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.
CVSS v3 Severity:9.1 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
7.9 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-125
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2018-17983

Source: XF
Type: UNKNOWN
mercurial-cve201817983-info-disc(150936)

Source: MISC
Type: Patch
https://www.mercurial-scm.org/repo/hg/rev/5405cb1a7901

Source: CCN
Type: Mercurial Web site
Mercurial 4.7.2 (2018-10-01)

Source: MISC
Type: Release Notes
https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.7.2_.282018-10-01.29

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mercurial:mercurial:*:*:*:*:*:*:*:* (Version < 4.7.2)

  • Configuration CCN 1:
  • cpe:/a:mercurial:mercurial:4.7.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201817983
    V
    CVE-2018-17983
    2023-06-22
    oval:org.opensuse.security:def:7718
    P
    mercurial-5.9.1-150400.1.8 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3124
    P
    libFLAC++6-1.3.0-11.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:2950
    P
    hplip-devel-3.21.10-150400.1.9 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94754
    P
    mercurial-5.9.1-150400.1.8 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2940
    P
    graphviz-2.48.0-150400.1.165 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:112980
    P
    mercurial-5.9.1-2.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:952
    P
    Security update for python39-pip (Moderate)
    2022-01-12
    oval:org.opensuse.security:def:64594
    P
    Security update for python-Pygments (Important)
    2021-10-20
    oval:org.opensuse.security:def:106427
    P
    mercurial-5.9.1-2.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:71381
    P
    python3-pycrypto-2.6.1-1.28 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71268
    P
    libjbig-devel-2.1-1.31 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:47934
    P
    zoo-2.10-1020.56 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47473
    P
    powerpc-utils-1.3.3-5.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47802
    P
    libvdpau1-1.1.1-6.73 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47609
    P
    fontconfig-2.11.1-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47488
    P
    quagga-0.99.22.1-15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47474
    P
    ppc64-diag-2.7.3-1.17 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48174
    P
    libpng16-16-1.6.8-14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48026
    P
    gnutls-3.3.27-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:2244
    P
    ipmitool-bmc-snmp-proxy-1.8.18+git20200204.7ccea28-1.22 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2234
    P
    dhcp-relay-4.3.5-6.6.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2295
    P
    vsftpd-3.0.3-7.16.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2229
    P
    apache2-mod_nss-1.0.17-3.3.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2289
    P
    stunnel-5.57-3.11.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2269
    P
    nginx-1.19.8-1.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2260
    P
    libslirp-devel-4.3.1-1.51 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2256
    P
    librabbitmq-devel-0.10.0-3.19 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2225
    P
    apache2-devel-2.4.43-3.17.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:68028
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15 SP1) (Important)
    2021-07-27
    oval:org.opensuse.security:def:1473
    P
    Security update for gupnp (Important)
    2021-06-24
    oval:org.opensuse.security:def:48743
    P
    libraw9-0.15.4-3.88 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48701
    P
    pidgin-otr-4.0.0-6.18 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48534
    P
    libpng12-0-1.2.50-13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48742
    P
    libqt4-sql-mysql-32bit-4.8.6-4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48630
    P
    sysconfig-0.84.0-13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48472
    P
    libXrender1-0.9.8-3.55 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48388
    P
    cpio-2.11-29.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48887
    P
    telepathy-idle-0.2.0-1.62 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48761
    P
    ImageMagick-6.8.8.1-33.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48599
    P
    perl-XML-LibXML-2.0019-5.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64681
    P
    Security update for p7zip (Moderate)
    2021-05-04
    oval:org.opensuse.security:def:2302
    P
    jakarta-taglibs-standard-1.1.1-2.42 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2300
    P
    apache2-mod_php7-7.2.5-2.9 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:51323
    P
    Security update for vim (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49487
    P
    python3-cupshelpers on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49943
    P
    dhcp-relay on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49330
    P
    sharutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49234
    P
    libsnmp30 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49914
    P
    mercurial on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49090
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67928
    P
    libplist++-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50047
    P
    apache2-mod_auth_openidc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49878
    P
    java-1_8_0-openjdk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51385
    P
    Security update for mercurial (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49860
    P
    perl-YAML-LibYAML on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49974
    P
    rarpd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49811
    P
    xorg-x11-server-sdk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49721
    P
    wavpack on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.xenial:def:2018179830000000
    V
    CVE-2018-17983 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-10-04
    oval:com.ubuntu.bionic:def:201817983000
    V
    CVE-2018-17983 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-10-04
    oval:com.ubuntu.disco:def:2018179830000000
    V
    CVE-2018-17983 on Ubuntu 19.04 (disco) - medium.
    2018-10-04
    oval:com.ubuntu.cosmic:def:201817983000
    V
    CVE-2018-17983 on Ubuntu 18.10 (cosmic) - medium.
    2018-10-04
    oval:com.ubuntu.cosmic:def:2018179830000000
    V
    CVE-2018-17983 on Ubuntu 18.10 (cosmic) - medium.
    2018-10-04
    oval:com.ubuntu.trusty:def:201817983000
    V
    CVE-2018-17983 on Ubuntu 14.04 LTS (trusty) - medium.
    2018-10-04
    oval:com.ubuntu.bionic:def:2018179830000000
    V
    CVE-2018-17983 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-10-04
    oval:com.ubuntu.xenial:def:201817983000
    V
    CVE-2018-17983 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-10-04
    BACK
    mercurial mercurial *
    mercurial mercurial 4.7.1