CVE-2018-13348: Mercurial Improper Input Validation vulnerability
(updated )
The mpatch_decode
function in mpatch.c
in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.
References
Detect and mitigate CVE-2018-13348 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →