CVE-2013-1436
code injection in xmonad-contrib
EPSS 9.0%
描述
The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the xmobar window title, as demonstrated using an action tag.
如何修補 CVE-2013-1436
要修補 CVE-2013-1436,請將受影響套件升級到下列已修補版本。
- Debian/xmonad-contrib—升級至 0.11.2-1 或更新版本
- Hackage/xmonad-contrib—升級至 0.11.2 或更新版本
CVE-2013-1436 正在被利用嗎?
中等 — EPSS 為 9.0%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 0.11.2-1
- >= 0.5, < 0.11.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 2.0 | — | AV:N/AC:L/Au:N/C:P/I:P/A:P |