CVE-2016-3068: Input Validation
Published Apr 13, 2016
·Updated
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
Affected Software
19 affected componentsFixes available
pip/mercurial<3.7.3
3.7.3
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Mercurial Mercurial<=3.7.2
Fedoraproject Fedora=22
Fedoraproject Fedora=23
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Hpc Node=7.0
redhat Enterprise Linux Hpc Node Eus=7.2
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.2
redhat Enterprise Linux Server Eus=7.2
redhat Enterprise Linux Workstation=7.0
SUSE Linux Enterprise Debuginfo=11-sp4
openSUSE openSUSE=13.2
SUSE Linux Enterprise Software Development Kit=11-sp4
SUSE Linux Enterprise Software Development Kit=12
SUSE Linux Enterprise Software Development Kit=12-sp1
openSUSE Leap=42.1
Remediation
Patch Available
Event History
Apr 13, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·02:08 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-3068?
CVE-2016-3068 is classified as a critical vulnerability due to the potential for remote arbitrary code execution.
2
How do I fix CVE-2016-3068?
To fix CVE-2016-3068, upgrade Mercurial to version 3.7.3 or later without delay.
3
Which versions of Mercurial are affected by CVE-2016-3068?
CVE-2016-3068 affects Mercurial versions prior to 3.7.3.
4
Can CVE-2016-3068 be exploited via the network?
Yes, CVE-2016-3068 can be exploited remotely when an attacker uses a crafted git ext:: URL.
5
What systems are impacted by CVE-2016-3068?
CVE-2016-3068 impacts multiple systems including Debian, Fedora, Red Hat, and SUSE distributions that use vulnerable versions of Mercurial.