id: PYSEC-2016-29 details: The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records. affected: - package: name: mercurial ecosystem: PyPI purl: pkg:pypi/mercurial ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 3.7.3 versions: - 0.8.1 - "0.9" - 0.9.1 - 0.9.2 - 0.9.3 - 0.9.4 - 0.9.5 - "1.0" - 1.0.1 - 1.0.2 - "1.1" - 1.1.1 - 1.1.2 - "1.2" - 1.2.1 - "1.3" - 1.3.1 - "1.4" - 1.4.1 - 1.4.2 - 1.4.3 - "1.5" - 1.5.1 - 1.5.2 - 1.5.3 - 1.5.4 - "1.6" - 1.6.1 - 1.6.2 - 1.6.3 - 1.6.4 - "1.7" - 1.7.1 - 1.7.2 - 1.7.3 - 1.7.5 - "1.8" - 1.8.1 - 1.8.2 - 1.8.3 - 1.8.4 - "1.9" - 1.9.1 - 1.9.2 - 1.9.3 - "2.0" - 2.0.1 - 2.0.2 - "2.1" - 2.1.1 - 2.1.2 - "2.2" - 2.2.2 - "2.3" - 2.4.1 - "2.5" - 2.5.1 - 2.5.2 - "2.6" - 2.6.1 - 2.6.2 - 2.6.3 - 2.7.0 - 2.7.1 - 2.7.2 - "2.8" - 2.8.1 - 2.8.2 - "2.9" - 2.9.1 - "3.0" - 3.0.1 - "3.1" - 3.1.1 - 3.1.2 - "3.2" - 3.2.1 - 3.2.2 - 3.2.3 - 3.2.4 - "3.3" - 3.3-rc - 3.3.1 - 3.3.2 - 3.3.3 - "3.4" - 3.4-rc - 3.4.1 - 3.4.2 - "3.5" - 3.5-rc - 3.5.1 - 3.5.2 - "3.6" - 3.6-rc - 3.6.1 - 3.6.2 - 3.6.3 - "3.7" - 3.7-rc - 3.7.1 - 3.7.2 references: - type: WEB url: http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00018.html - type: WEB url: http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00017.html - type: WEB url: http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181505.html - type: WEB url: https://selenic.com/repo/hg-stable/rev/b6ed2505d6cf - type: WEB url: https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_3.7.3_.282016-3-29.29 - type: WEB url: http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181542.html - type: ADVISORY url: http://www.debian.org/security/2016/dsa-3542 - type: WEB url: http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00016.html - type: WEB url: https://selenic.com/repo/hg-stable/rev/b9714d958e89 - type: WEB url: http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00043.html - type: WEB url: http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html - type: ADVISORY url: https://security.gentoo.org/glsa/201612-19 - type: ADVISORY url: https://github.com/advisories/GHSA-9vjf-jjcq-3gh7 aliases: - CVE-2016-3630 - GHSA-9vjf-jjcq-3gh7 modified: "2021-08-27T03:22:06.971468Z" published: "2016-04-13T16:59:00Z"