CVE-2008-2942
Mercurial Directory traversal vulnerability
EPSS 1.9%
Description
Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.
How to fix CVE-2008-2942
To remediate CVE-2008-2942, upgrade the affected package to a fixed version below.
- PyPI/mercurial—upgrade to 1.0.2 or later
- PyPI/mercurial—upgrade to 1.0.2 or later
Is CVE-2008-2942 being exploited?
Low — EPSS is 1.9%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.0.2
- from 0, < 1.0.2