osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:36
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-updates/2012-03/msg00035.html - | |
References | () http://www.openwall.com/lists/oss-security/2012/02/28/15 - | |
References | () http://www.openwall.com/lists/oss-security/2012/02/28/9 - | |
References | () http://www.openwall.com/lists/oss-security/2012/03/02/2 - | |
References | () https://bugzilla.novell.com/show_bug.cgi?id=749335 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=798353 - |
Information
Published : 2014-02-06 17:00
Updated : 2024-11-21 01:36
NVD link : CVE-2012-1095
Mitre link : CVE-2012-1095
CVE.ORG link : CVE-2012-1095
JSON object : View
Products Affected
opensuse
- osc
- opensuse
CWE
CWE-264
Permissions, Privileges, and Access Controls