CVE-2017-9462: Critical severity Mercurial Mercurial vulnerability
Published Jun 6, 2017
·Updated
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.
Affected Software
20 affected componentsFixes available
redhat/mercurial<4.1.3
4.1.3
pip/mercurial<4.1.3
4.1.3
Mercurial Mercurial<4.1.3
Debian Debian Linux=8.0
Debian Debian Linux=9.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Eus=7.3
redhat Enterprise Linux Server Eus=7.4
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Server Tus=7.3
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
Remediation
Patch Available
Event History
Jun 6, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Jul 13, 2018
Advisory Published
via GitHub·03:17 PM
Frequently Asked Questions
1
What is the severity of CVE-2017-9462?
CVE-2017-9462 is considered a medium severity vulnerability because it allows remote authenticated users to execute arbitrary code.
2
How do I fix CVE-2017-9462?
To fix CVE-2017-9462, upgrade Mercurial to version 4.1.3 or later.
3
What software is affected by CVE-2017-9462?
CVE-2017-9462 affects Mercurial versions prior to 4.1.3, specifically on platforms like Debian and Red Hat Enterprise Linux.
4
What type of attack does CVE-2017-9462 enable?
CVE-2017-9462 enables remote authenticated users to launch the Python debugger, potentially leading to arbitrary code execution.
5
Is CVE-2017-9462 present in the latest versions of Mercurial?
No, CVE-2017-9462 is not present in Mercurial version 4.1.3 and later, as it has been patched.