CVE-2016-3630: High severity red hat fedora vulnerability
Published Apr 13, 2016
·Updated
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
Affected Software
12 affected componentsFixes available
pip/mercurial<3.7.3
3.7.3
Fedoraproject Fedora=22
Fedoraproject Fedora=23
openSUSE Leap=42.1
Mercurial Mercurial<=3.7.2
Debian Debian Linux=7.0
Debian Debian Linux=8.0
SUSE Linux Enterprise Debuginfo=11-sp4
openSUSE openSUSE=13.2
SUSE Linux Enterprise Software Development Kit=11-sp4
SUSE Linux Enterprise Software Development Kit=12
SUSE Linux Enterprise Software Development Kit=12-sp1
Event History
Apr 13, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·02:08 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-3630?
CVE-2016-3630 is classified as a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2016-3630?
To fix CVE-2016-3630, upgrade Mercurial to version 3.7.3 or later.
3
Which versions of Mercurial are affected by CVE-2016-3630?
Mercurial versions prior to 3.7.3 are affected by CVE-2016-3630.
4
Can CVE-2016-3630 be exploited remotely?
Yes, CVE-2016-3630 can be exploited remotely through clone, push, or pull commands.
5
What types of attacks are associated with CVE-2016-3630?
CVE-2016-3630 is associated with arbitrary code execution due to list sizing rounding errors and issues with short records.