*** This bug is a security vulnerability *** Public security bug reported:
A security flaw was found in the way osc displayed build logs and build status for particular build. A rogue repository server could use this flaw to modify window's title, or possibly execute arbitrary commands or overwrite files via a specially-crafted build log or build status output containing an escape sequence for a terminal emulator. Reference: https://bugzilla.novell.com/show_bug.cgi?id=749335 Upstream patch: https://github.com/openSUSE/osc/commit/effe3835ba65745f51dbb579af4ea3556d2ab597.patch ** Affects: osc (Ubuntu) Importance: Undecided Status: New ** Information type changed from Private Security to Public Security ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2012-1095 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1197639 Title: Improper sanitization of terminal emulator escape sequences when displaying build log and build status To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/osc/+bug/1197639/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs