CVE-2016-3069: Input Validation
Published Apr 13, 2016
·Updated
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.
Affected Software
19 affected componentsFixes available
pip/mercurial<3.7.3
3.7.3
Mercurial Mercurial<=3.7.2
Debian Debian Linux=7.0
Debian Debian Linux=8.0
SUSE Linux Enterprise Debuginfo=11-sp4
openSUSE openSUSE=13.2
SUSE Linux Enterprise Software Development Kit=11-sp4
SUSE Linux Enterprise Software Development Kit=12
SUSE Linux Enterprise Software Development Kit=12-sp1
openSUSE Leap=42.1
Fedoraproject Fedora=22
Fedoraproject Fedora=23
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Hpc Node=7.0
redhat Enterprise Linux Hpc Node Eus=7.2
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.2
redhat Enterprise Linux Server Eus=7.2
redhat Enterprise Linux Workstation=7.0
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Apr 13, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·02:08 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-3069?
CVE-2016-3069 is classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2016-3069?
To fix CVE-2016-3069, upgrade Mercurial to version 3.7.3 or later.
3
What impact does CVE-2016-3069 have on affected systems?
CVE-2016-3069 allows attackers to execute arbitrary code, posing a significant risk to the integrity and security of affected systems.
4
Which versions of Mercurial are affected by CVE-2016-3069?
Mercurial versions prior to 3.7.3 are affected by CVE-2016-3069.
5
Can CVE-2016-3069 be exploited remotely?
Yes, CVE-2016-3069 can be exploited by remote attackers through a crafted name when converting a Git repository.