openSUSE OSC Escape Sequence in Build Log and Build Status Command Injection Vulnerability
BID:65658
Info
openSUSE OSC Escape Sequence in Build Log and Build Status Command Injection Vulnerability
| Bugtraq ID: | 65658 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-1095 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2012 12:00AM |
| Updated: | Feb 28 2012 12:00AM |
| Credit: | Jan Lieskovsky |
| Vulnerable: |
openSUSE OSC 0.133 |
| Not Vulnerable: | |
Discussion
openSUSE OSC Escape Sequence in Build Log and Build Status Command Injection Vulnerability
openSUSE OSC is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary commands in the context of the application.
openSUSE OSC 11.4 and 12.1 are vulnerable; other versions may also be affected.
openSUSE OSC is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary commands in the context of the application.
openSUSE OSC 11.4 and 12.1 are vulnerable; other versions may also be affected.
Exploit / POC
openSUSE OSC Escape Sequence in Build Log and Build Status Command Injection Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
openSUSE OSC Escape Sequence in Build Log and Build Status Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
openSUSE OSC Escape Sequence in Build Log and Build Status Command Injection Vulnerability
References:
References: