CVE-2014-9462: Input Validation
Published Mar 31, 2015
·Updated
The validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.
Affected Software
4 affected componentsFixes available
pip/mercurial<3.2.4
3.2.4
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Mercurial Mercurial<=3.2.3
Event History
Mar 31, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·02:05 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-9462?
CVE-2014-9462 has a high severity rating due to its ability to allow remote command execution.
2
How do I fix CVE-2014-9462?
To fix CVE-2014-9462, upgrade Mercurial to version 3.2.4 or later.
3
What software is affected by CVE-2014-9462?
CVE-2014-9462 affects Mercurial versions prior to 3.2.4 and specific versions of openSUSE.
4
How does CVE-2014-9462 exploit vulnerabilities?
CVE-2014-9462 exploits vulnerabilities through a crafted repository name in a clone command, allowing arbitrary command execution.
5
Who can be impacted by CVE-2014-9462?
Remote attackers can potentially impact users of vulnerable Mercurial versions and systems running affected openSUSE versions.