CVE-2018-13347: Integer Overflow
mpatch.c in Mercurial before 4.6.1 mishandles integer addition and subtraction, aka OVE-20180430-0002.
Other sources
Mercurial before version 4.6.1 is vulnerable to a buffer underflow in mpatch.c:mpatchapply().
Upstream Changelog:
https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial4.6.1.282018-06-06.29
Upstream Patch:
https://www.mercurial-scm.org/repo/hg/rev/1acfc35d478c
— Red Hat
mpatch.c in Mercurial before 4.6.1 mishandles integer addition and subtraction, aka OVE-20180430-0002.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-13347.
What is the severity of CVE-2018-13347?
CVE-2018-13347 has a severity rating of 9.8 (Critical).
What is the affected software?
The affected software is Mercurial before version 4.6.1.
How does CVE-2018-13347 affect Mercurial?
CVE-2018-13347 in Mercurial mishandles integer addition and subtraction, which can lead to security vulnerabilities.
How can I fix CVE-2018-13347?
To fix CVE-2018-13347, update Mercurial to version 4.6.1 or later.