QID 198582

Date Published: 2021-11-30

QID 198582: Ubuntu Security Notification for Mercurial Vulnerabilities (USN-5102-1)

It was discovered that Mercurial mishandled symlinks in subrepositories and incorrectly handled certain manifest files.

An attacker could use this issue to write arbitrary files to the target filesystem and to cause a denial of service and possibly execute arbitrary code

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Refer to Ubuntu advisory USN-5102-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198582

    Software Advisories
    Advisory ID Software Component Link
    USN-5102-1 URL Logo ubuntu.com/security/notices/USN-5102-1