REDHAT-BUG-798353: Low severity openSUSE osc vulnerability
A security flaw was found in the way osc, the Python language based command line client for the openSUSE build service, displayed build logs and build status for particular build. A rogue repository server could use this flaw to modify window's title, or possibly execute arbitrary commands or overwrite files via a specially-crafted build log or build status output containing an escape sequence for a terminal emulator.
References: [1] https://bugzilla.novell.com/showbug.cgi?id=749335
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-798353?
The severity of REDHAT-BUG-798353 is considered moderate due to potential arbitrary command execution.
How do I fix REDHAT-BUG-798353?
To fix REDHAT-BUG-798353, ensure that you are running the latest version of the openSUSE osc client.
What systems are affected by REDHAT-BUG-798353?
Systems using the openSUSE osc client are affected by REDHAT-BUG-798353.
What kind of exploit is possible with REDHAT-BUG-798353?
A rogue repository server could exploit REDHAT-BUG-798353 to modify window titles or execute arbitrary commands.
Is there a known workaround for REDHAT-BUG-798353?
Currently, the best practice is to regularly update the openSUSE osc client to mitigate risks associated with REDHAT-BUG-798353.