CVE-2013-1436

high
Published 2014-10-06 · Modified 2026-05-06
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the xmobar window title, as demonstrated using an action tag.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-1436

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://handra.rampa.sk/dawb/patch?repoPURL=http%3A%2F%2Fcode.haskell.org%2FXMonadContrib&repoPHash=20130708144813-1499c-0c3e284d3523c0694b9423714081761813bc1e89

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.11.2-1
debian debianbullseyefixed0.11.2-1
debian debianforkyfixed0.11.2-1
debian debiansidfixed0.11.2-1
debian debiantrixiefixed0.11.2-1

Application impact

VendorProductVersionsFixed
xmonadxmonad-contrab{"endIncluding":"0.11.1"}
xmonadxmonad-contrab0.11

References

CWEs

CWE-94

Verify integrity in audit chain (admin only). AS-IS.