Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text, or trigger emulator-specific behavior when victims run onefetch.
I am monitoring the upstream bug https://github.com/o2sh/onefetch/issues/1828 and the proposed fix in https://github.com/o2sh/onefetch/pull/1829. I am inclined to allow a little more time for discussion to run its course, and ideally for the fix to be at least merged upstream, before applying a downstream patch. Since the proposed fix is in the main onefetch crate, corresponding to the rust-onefetch package, Iām closing bugs filed against rust-onefetch-ascii, rust-onefetch-image, and rust-onefetch-manifest. *** This bug has been marked as a duplicate of bug 2542294 ***