Junglewise Threat Intelligence

CVE-2014-9462: PYSEC-2015-14 - The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted reposito

CVE-2014-9462 · Severity: low · CVSS 3.1 · Published 2015-03-31

Technologies: mercurial (PyPI). Vendors: PyPI.

Executive brief

Mercurial is a distributed version control system used to manage source code repositories. A vulnerability in the SSH peer component allows attackers to execute arbitrary commands on systems when cloning a repository with a specially crafted name, potentially leading to complete system compromise without requiring authentication.

Technical details

The vulnerability exists in the _validaterepo function in sshpeer, which insufficiently validates repository names passed to the clone command. An attacker can inject shell metacharacters into a repository name to execute arbitrary commands with the privileges of the user running the clone operation. The attack is network-accessible and requires no authentication or user interaction beyond initiating a clone operation. A successful exploit allows remote code execution. The vulnerability was fixed in version 3.2.4, with earlier versions (0.x through 3.2.3) affected.

Affected products

  • Mercurial Mercurial before 3.2.4

Timeline

  • 2015-03-31: disclosed: NVD publication date
  • 2015: patched: Version 3.2.4 released with fix
  • 2022-05-14: advisory: GHSA advisory published

References

Related threats