Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-4297

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2008-4297
Last Modified 07 Mar 2011 10:12:13
Published 27 Sep 2008 06:30:03
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-4297

Summary

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.

Vulnerable Systems

Application

  • Mercurial 1.0.1


References

CONFIRM - https://issues.rpath.com/browse/RPL-2753

XF - mercurial-allowpull-info-disclosure(45229)

VUPEN - ADV-2008-2604

CONFIRM - http://www.selenic.com/mercurial/wiki/index.cgi/WhatsNew#head-905b8adb3420a77d92617e06590055bd8952e02b

BID - 31223

BUGTRAQ - 20080917 rPSA-2008-0276-1 mercurial mercurial-hgk

CONFIRM - http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0276

SECUNIA - 32182

MLIST - [oss-security] 20080918 CVE Request (mercurial)

SUSE - SUSE-SR:2008:020


Last Updated: 27 May 2016 10:48:27