CVE-2013-1436
06.10.2014, 23:55
The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the xmobar window title, as demonstrated using an action tag.
| Vendor | Product | Version |
|---|---|---|
| xmonad | xmonad-contrab | 𝑥 ≤ 0.11.1 |
| xmonad | xmonad-contrab | 0.11 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References