Junglewise Threat Intelligence

CVE-2018-13348: PYSEC-2018-90 - The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remai

CVE-2018-13348 · Severity: low · CVSS 3 · Published 2018-07-06

Technologies: mercurial (PyPI). Vendors: PyPI.

Executive brief

The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.

Affected products

  • PyPI mercurial

Related threats