Executive brief
The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.
Affected products
- PyPI mercurial
Junglewise Threat Intelligence
CVE-2016-3105 · Severity: low · CVSS 3 · Published 2016-05-09
Technologies: mercurial (PyPI). Vendors: PyPI.
The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.