osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.
| Software | From | Fixed in |
|---|---|---|
| opensuse / opensuse | 11.4 | 11.4.x |
| opensuse / osc | - | 0.133.x |
| opensuse / opensuse | 12.1 | 12.1.x |