CVE-2013-1436
code injection in xmonad-contrib
EPSS 9.0%
Description
The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the xmobar window title, as demonstrated using an action tag.
How to fix CVE-2013-1436
To remediate CVE-2013-1436, upgrade the affected package to a fixed version below.
- Debian/xmonad-contrib—upgrade to 0.11.2-1 or later
- Hackage/xmonad-contrib—upgrade to 0.11.2 or later
Is CVE-2013-1436 being exploited?
Moderate — EPSS is 9.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 0.11.2-1
- >= 0.5, < 0.11.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 2.0 | — | AV:N/AC:L/Au:N/C:P/I:P/A:P |