Amazon Linux AMI : mercurial (ALAS-2016-697)

high Nessus Plugin ID 90866

Synopsis

The remote Amazon Linux AMI host is missing a security update.

Description

It was discovered that Mercurial failed to properly check Git sub-repository URLs. A Mercurial repository that includes a Git sub-repository with a specially crafted URL could cause Mercurial to execute arbitrary code. (CVE-2016-3068)

The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records. (CVE-2016-3630)

It was discovered that the Mercurial convert extension failed to sanitize special characters in Git repository names. A Git repository with a specially crafted name could cause Mercurial to execute arbitrary code when the Git repository was converted to a Mercurial repository. (CVE-2016-3069)

Solution

Run 'yum update mercurial' to update your system.

See Also

https://alas.aws.amazon.com/ALAS-2016-697.html

Plugin Details

Severity: High

ID: 90866

File Name: ala_ALAS-2016-697.nasl

Version: 2.3

Type: local

Agent: unix

Published: 5/4/2016

Updated: 4/18/2018

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:mercurial-debuginfo, p-cpe:/a:amazon:linux:emacs-mercurial, p-cpe:/a:amazon:linux:mercurial-common, p-cpe:/a:amazon:linux:mercurial-python27, p-cpe:/a:amazon:linux:mercurial-python26, cpe:/o:amazon:linux, p-cpe:/a:amazon:linux:emacs-mercurial-el

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Patch Publication Date: 5/3/2016

Reference Information

CVE: CVE-2016-3068, CVE-2016-3069, CVE-2016-3630

ALAS: 2016-697