Junglewise Threat Intelligence

CVE-2017-17458: PYSEC-2017-90 - In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the f

CVE-2017-17458 · Severity: low · CVSS 3 · Published 2017-12-07

Technologies: mercurial (PyPI). Vendors: PyPI.

Executive brief

In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.

Affected products

  • PyPI mercurial

Related threats