*** This bug is a security vulnerability ***

Public security bug reported:

A security flaw was found in the way osc displayed build logs and build
status for particular build. A rogue repository server could use this
flaw to modify window's title, or possibly execute arbitrary commands or
overwrite files via a specially-crafted build log or build status output
containing an escape sequence for a terminal emulator.

Reference:
https://bugzilla.novell.com/show_bug.cgi?id=749335

Upstream patch:
https://github.com/openSUSE/osc/commit/effe3835ba65745f51dbb579af4ea3556d2ab597.patch

** Affects: osc (Ubuntu)
     Importance: Undecided
         Status: New

** Information type changed from Private Security to Public Security

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2012-1095

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1197639

Title:
   Improper sanitization of terminal emulator escape sequences when
  displaying build log and build status

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/osc/+bug/1197639/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to