CVE-2012-1095: Opensuse

Medium severity, CVSS 4.3. EPSS: 1.4% chance of exploitation in the next 30 days.

osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.

Affected products

  • Opensuse Opensuse: version 11.4 only; version 12.1 only
  • Opensuse Osc: up to and including 0.133

Published 2014-02-06. Last modified 2026-06-16.