CVE-2010-4237: Medium severity Mercurial Mercurial vulnerability
Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2010-4237?
CVE-2010-4237 is a vulnerability in Mercurial before 1.6.4 that allows remote attackers to perform a man-in-the-middle attack.
How does CVE-2010-4237 work?
CVE-2010-4237 occurs because Mercurial fails to verify the Common Name field of SSL certificates, allowing attackers with a certificate signed by a Certificate Authority to perform a man-in-the-middle attack.
What is the severity of CVE-2010-4237?
The severity of CVE-2010-4237 is medium, with a severity value of 5.9.
What software versions are affected by CVE-2010-4237?
Mercurial versions up to and excluding 1.6.4 are affected by CVE-2010-4237.
How can I fix CVE-2010-4237?
To fix CVE-2010-4237, upgrade Mercurial to version 1.6.4 or later.