Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations
NameCVE-2017-17458First vendor Publication2017-12-07
VendorCveLast vendor Modification2019-03-14

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score10Attack RangeNetwork
Cvss Impact Score10Attack ComplexityLow
Cvss Expoit Score10AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17458

CWE : Common Weakness Enumeration

%idName
100 %CWE-78Improper Sanitization of Special Elements used in an OS Command ('OS Command Injection') (CWE/SANS Top 25)

CPE : Common Platform Enumeration

TypeDescriptionCount
Application111
Os2

Nessus® Vulnerability Scanner

DateDescription
2018-07-06Name : The remote Debian host is missing a security update.
File : debian_DLA-1414.nasl - Type : ACT_GATHER_INFO
2018-02-16Name : The version of Atlassian SourceTree installed on the remote Windows host is a...
File : atlassian_sourcetree_2_4_7_0.nasl - Type : ACT_GATHER_INFO
2017-12-29Name : The remote Debian host is missing a security update.
File : debian_DLA-1224.nasl - Type : ACT_GATHER_INFO
2017-12-18Name : The remote openSUSE host is missing a security update.
File : openSUSE-2017-1388.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

SourceUrl
BID http://www.securityfocus.com/bid/102926
CONFIRM https://confluence.atlassian.com/sourcetreekb/sourcetree-security-advisory-20...
MISC https://bz.mercurial-scm.org/show_bug.cgi?id=5730
https://www.mercurial-scm.org/pipermail/mercurial-devel/2017-November/107333....
https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.4.1_.282017-11-07.29
MLIST https://lists.debian.org/debian-lts-announce/2017/12/msg00027.html
https://lists.debian.org/debian-lts-announce/2018/07/msg00005.html
https://lists.debian.org/debian-lts-announce/2018/07/msg00041.html

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
DateInformations
2019-05-01 12:08:22
  • Multiple Updates
2019-03-14 17:19:21
  • Multiple Updates
2018-07-29 09:19:25
  • Multiple Updates
2018-07-09 05:18:01
  • Multiple Updates
2018-02-08 09:20:06
  • Multiple Updates
2018-02-05 13:21:36
  • Multiple Updates
2018-01-27 09:19:49
  • Multiple Updates
2017-12-22 21:22:08
  • Multiple Updates
2017-12-19 13:23:50
  • Multiple Updates
2017-12-07 21:22:47
  • First insertion