UBUNTU-CVE-2013-1436
Dashboard / Vulnerabilities / UBUNTU-CVE-2013-1436
Summary:
Details: The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the xmobar window title, as demonstrated using an action tag.
References: https://ubuntu.com/security/CVE-2013-1436, https://www.cve.org/CVERecord?id=CVE-2013-1436
Affected packages
Package
Name: xmonad-contrib
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -0.11.2-1build1
Affected versions
0.11.2-1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
