CVE-2012-1095
published 2014-02-06CVE-2012-1095: osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status…
PriorityP427medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.36%
68.6th percentile
osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | osc | < osc 0.134.0-1 (bookworm) | osc 0.134.0-1 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | osc | <= 0.133 | — |
| opensuse | osc | >= 0 < 0.134.0-1 | 0.134.0-1 |
| opensuse | osc | >= 0 < 0.134.0-1 | 0.134.0-1 |
| opensuse | osc | >= 0 < 0.134.0-1 | 0.134.0-1 |
| opensuse | osc | >= 0 < 0.134.0-1 | 0.134.0-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7rm7-fgx5-3w4w: osc before 0
ghsa_unreviewed·2022-05-14
CVE-2012-1095 [MEDIUM] GHSA-7rm7-fgx5-3w4w: osc before 0
osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.
OSV
CVE-2012-1095: osc before 0
osv·2014-02-06·CVSS 4.3
CVE-2012-1095 [MEDIUM] CVE-2012-1095: osc before 0
osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.
Debian
CVE-2012-1095: osc - osc before 0.134 might allow remote OBS repository servers or package maintainer...
vendor_debian·2012·CVSS 4.3
CVE-2012-1095 [MEDIUM] CVE-2012-1095: osc - osc before 0.134 might allow remote OBS repository servers or package maintainer...
osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.
Scope: local
bookworm: resolved (fixed in 0.134.0-1)
bullseye: resolved (fixed in 0.134.0-1)
forky: resolved (fixed in 0.134.0-1)
sid: resolved (fixed in 0.134.0-1)
trixie: resolved (fixed in 0.134.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1095 osc: Improper sanitization of terminal emulator escape sequences when displaying build log and build status [epel-6]
bugzilla·2012-03-02·CVSS 4.3
CVE-2012-1095 [MEDIUM] CVE-2012-1095 osc: Improper sanitization of terminal emulator escape sequences when displaying build log and build status [epel-6]
CVE-2012-1095 osc: Improper sanitization of terminal emulator escape sequences when displaying build log and build status [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
http
Bugzilla
CVE-2012-1095 osc: Improper sanitization of terminal emulator escape sequences when displaying build log and build status [fedora-all]
bugzilla·2012-03-02·CVSS 4.3
CVE-2012-1095 [MEDIUM] CVE-2012-1095 osc: Improper sanitization of terminal emulator escape sequences when displaying build log and build status [fedora-all]
CVE-2012-1095 osc: Improper sanitization of terminal emulator escape sequences when displaying build log and build status [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
Bugzilla
CVE-2012-1095 osc: Improper sanitization of terminal emulator escape sequences when displaying build log and build status
bugzilla·2012-02-28·CVSS 4.3
CVE-2012-1095 [MEDIUM] CVE-2012-1095 osc: Improper sanitization of terminal emulator escape sequences when displaying build log and build status
CVE-2012-1095 osc: Improper sanitization of terminal emulator escape sequences when displaying build log and build status
A security flaw was found in the way osc, the Python language based command line client for the openSUSE build service, displayed build logs and build status for particular build. A rogue repository server could use this flaw to modify window's title, or possibly execute arbitrary commands or overwrite files via a specially-crafted build log or build status output containing an escape sequence for a terminal emulator.
References:
[1] https://bugzilla.novell.com/show_bug.cgi?id=749335
Discussion:
CVE request:
[2] http://www.openwall.com/lists/oss-security/2012/02/28/9
---
The CVE identifier of CVE-2012-1095 has been assigned to this issue:
[3] http://www.openwall.c
http://lists.opensuse.org/opensuse-updates/2012-03/msg00035.htmlhttp://www.openwall.com/lists/oss-security/2012/02/28/15http://www.openwall.com/lists/oss-security/2012/02/28/9http://www.openwall.com/lists/oss-security/2012/03/02/2https://bugzilla.novell.com/show_bug.cgi?id=749335https://bugzilla.redhat.com/show_bug.cgi?id=798353http://lists.opensuse.org/opensuse-updates/2012-03/msg00035.htmlhttp://www.openwall.com/lists/oss-security/2012/02/28/15http://www.openwall.com/lists/oss-security/2012/02/28/9http://www.openwall.com/lists/oss-security/2012/03/02/2https://bugzilla.novell.com/show_bug.cgi?id=749335https://bugzilla.redhat.com/show_bug.cgi?id=798353
2014-02-06
Published