First published: Mon Jun 30 2008(Updated: )
Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/mercurial | <1.0.2 | 1.0.2 |
Mercurial | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2942 has a medium severity level due to the potential for unauthorized file modifications.
To fix CVE-2008-2942, upgrade Mercurial to version 1.0.2 or later.
CVE-2008-2942 is caused by a directory traversal vulnerability in the patch.py file of Mercurial prior to version 1.0.2.
CVE-2008-2942 affects Mercurial version 1.0.1 and earlier.
Yes, exploiting CVE-2008-2942 could potentially allow attackers to compromise other files on the system.