Moderate severityNVD Advisory· Published Apr 22, 2019· Updated Aug 4, 2024
CVE-2019-3902
CVE-2019-3902
Description
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mercurialPyPI | < 4.9 | 4.9 |
Affected products
8- ghsa-coords7 versionspkg:pypi/mercurialpkg:rpm/opensuse/mercurial&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/mercurial&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/mercurial&distro=openSUSE%20Tumbleweedpkg:rpm/suse/mercurial&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP1pkg:rpm/suse/mercurial&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP2pkg:rpm/suse/mercurial&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 4.9+ 6 more
- (no CPE)range: < 4.9
- (no CPE)range: < 4.5.2-lp151.6.3.1
- (no CPE)range: < 4.5.2-lp152.7.3.1
- (no CPE)range: < 5.9.1-2.1
- (no CPE)range: < 4.5.2-3.9.44
- (no CPE)range: < 4.5.2-3.9.44
- (no CPE)range: < 2.8.2-15.18.4
Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-mq66-vcfc-8246ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-3902ghsaADVISORY
- usn.ubuntu.com/4086-1/mitrevendor-advisoryx_refsource_UBUNTU
- bugzilla.redhat.com/show_bug.cgighsax_refsource_CONFIRMWEB
- github.com/pypa/advisory-database/tree/main/vulns/mercurial/PYSEC-2019-188.yamlghsaWEB
- lists.debian.org/debian-lts-announce/2019/04/msg00024.htmlghsamailing-listx_refsource_MLISTWEB
- lists.debian.org/debian-lts-announce/2020/07/msg00032.htmlghsamailing-listx_refsource_MLISTWEB
- usn.ubuntu.com/4086-1ghsaWEB
- www.mercurial-scm.org/wiki/WhatsNewghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.