A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services
A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 100.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 100.00 |
VPI formula vpi-v1