First published: Fri Jun 22 2018(Updated: )
`mpatch.c` in Mercurial before 4.6.1 mishandles integer addition and subtraction, aka OVE-20180430-0002.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mercurial Mercurial | <4.6.1 | |
redhat/mercurial | <4.6.1 | 4.6.1 |
pip/mercurial | <4.6.1 | 4.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-13347.
CVE-2018-13347 has a severity rating of 9.8 (Critical).
The affected software is Mercurial before version 4.6.1.
CVE-2018-13347 in Mercurial mishandles integer addition and subtraction, which can lead to security vulnerabilities.
To fix CVE-2018-13347, update Mercurial to version 4.6.1 or later.