First published: Tue Feb 28 2012(Updated: )
A security flaw was found in the way osc, the Python language based command line client for the openSUSE build service, displayed build logs and build status for particular build. A rogue repository server could use this flaw to modify window's title, or possibly execute arbitrary commands or overwrite files via a specially-crafted build log or build status output containing an escape sequence for a terminal emulator. References: [1] <a href="https://bugzilla.novell.com/show_bug.cgi?id=749335">https://bugzilla.novell.com/show_bug.cgi?id=749335</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Opensuse Osc | <=0.133 | |
openSUSE openSUSE | =11.4 | |
openSUSE openSUSE | =12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.