xmonad XMonad.Hooks.DynamicLog Module Multiple Remote Command Injection Vulnerabilities
BID:61491
Info
xmonad XMonad.Hooks.DynamicLog Module Multiple Remote Command Injection Vulnerabilities
| Bugtraq ID: | 61491 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-1436 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2013 12:00AM |
| Updated: | Apr 13 2015 09:15PM |
| Credit: | Joachim Breitner and the Debian Security Team. |
| Vulnerable: |
Gentoo Linux Don Stewart XMonad.Hooks.DynamicLog 0 |
| Not Vulnerable: | |
Discussion
xmonad XMonad.Hooks.DynamicLog Module Multiple Remote Command Injection Vulnerabilities
XMonad.Hooks.DynamicLog module for xmonad is prone to multiple remote command-injection vulnerabilities.
Successful exploits will result in the execution of arbitrary commands in the context of the affected applications. This may aid in further attacks.
XMonad.Hooks.DynamicLog module for xmonad is prone to multiple remote command-injection vulnerabilities.
Successful exploits will result in the execution of arbitrary commands in the context of the affected applications. This may aid in further attacks.
Exploit / POC
xmonad XMonad.Hooks.DynamicLog Module Multiple Remote Command Injection Vulnerabilities
An attacker can exploit these issues using a web browser.
The following example data is available:
An attacker can exploit these issues using a web browser.
The following example data is available:
Solution / Fix
xmonad XMonad.Hooks.DynamicLog Module Multiple Remote Command Injection Vulnerabilities
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
xmonad XMonad.Hooks.DynamicLog Module Multiple Remote Command Injection Vulnerabilities
References:
References:
- CVE-2013-1436: xmonad-contrib remote command injection (Raúl Benencia)
- Xmonad Homepage (xmonad.org)
- XMonad.Hooks.DynamicLog page (Don Stewart)