Comment 4 for bug 1197639

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package osc - 0.132.6-1ubuntu0.1

---------------
osc (0.132.6-1ubuntu0.1) precise-security; urgency=low

  * SECURITY UPDATE: Improper sanitization of terminal emulator escape
    sequences when displaying build log and build status (LP: #1197639)
    - debian/patches/CVE-2012-1095.patch: osc/core.py(print_buildlog): strip
      terminal control chars, except new lines from build logs. Based on
      upstream patch.
    - CVE-2012-1095
 -- Christian Kuersteiner <email address hidden> Tue, 16 Jul 2013 11:44:28 +0700