Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mercurial | Oct 4, 2017 | Oct 4, 2017 |
| Amazon_linux | — | Upgrade mercurial | Dec 20, 2017 | Sep 13, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 4, 2017 |
| Centos_linux | — | Upgrade mercurial-debuginfoUpgrade mercurial-hgkUpgrade mercurialUpgrade emacs-mercurialUpgrade emacs-mercurial-el | Aug 28, 2019 | Oct 5, 2017 |
| Debian | — | Upgrade mercurial | Dec 4, 2017 | Sep 4, 2017 |
| Freebsd | — | Upgrade mercurial | Oct 16, 2017 | Oct 16, 2017 |
| Gentoo Linux | — | Upgrade dev-vcs/mercurial. | Oct 30, 2017 | Oct 4, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade mercurial | Nov 30, 2017 | Oct 4, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade mercurial | Nov 30, 2017 | Oct 4, 2017 |
| Oracle Solaris | — | Upgrade developer/versioning/mercurial-27 to version 4.7.1-11.4.7.0.1.3.0 on Solaris 11.4Upgrade developer/versioning/mercurial to version 4.7.1-11.4.7.0.1.3.0 on Solaris 11.4Upgrade developer/versioning/mercurial to version 4.1.3-0.175.3.24.0.2.0 on Solaris 11.3Upgrade developer/versioning/mercurial-27 to version 4.1.3-0.175.3.24.0.2.0 on Solaris 11.3Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Sep 19, 2017 | Sep 19, 2017 |
| Oracle_linux | — | Upgrade mercurial-hgkUpgrade emacs-mercurial-elUpgrade mercurialUpgrade emacs-mercurial | Dec 20, 2017 | Aug 10, 2017 |
| Redhat_linux | — | No solution existsUpgrade mercurial-hgkUpgrade mercurialUpgrade emacs-mercurialUpgrade mercurial-debuginfoUpgrade emacs-mercurial-el | Jan 17, 2018 | Aug 17, 2017 |
| Suse | — | Upgrade mercurial | Jan 26, 2018 | Aug 24, 2017 |
| Ubuntu | — | Upgrade mercurial | Nov 19, 2024 | Oct 5, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 4, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub