CVE-2013-1436
06.10.2014, 23:55
The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the xmobar window title, as demonstrated using an action tag.
Vendor | Product | Version |
---|---|---|
xmonad | xmonad-contrab | 𝑥 ≤ 0.11.1 |
xmonad | xmonad-contrab | 0.11 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References