CVE-2012-1095

Publication date 6 February 2014

Last updated 24 July 2024


Ubuntu priority

Description

osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.

Status

Package Ubuntu Release Status
osc 13.04 raring
Not affected
12.10 quantal
Not affected
12.04 LTS precise
Fixed 0.132.6-1ubuntu0.1
11.10 oneiric Ignored end of life
11.04 natty Ignored end of life
10.10 maverick Ignored end of life
10.04 LTS lucid Ignored end of life
8.04 LTS hardy Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
osc