Executive brief
cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.
Affected products
- PyPI mercurial
Junglewise Threat Intelligence
CVE-2018-17983 · Severity: low · CVSS 3 · Published 2018-10-04
Technologies: mercurial (PyPI). Vendors: PyPI.
cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.