Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Gentoo: GLSA-201405-28 Normal: xmonad-contrib Arbitrary Code Execution

gentoo
Calendar Grey May 28, 2014
Scroller Gentoo
A critical security flaw has been identified in xmonad-contrib on Gentoo, which may allow attackers to execute arbitrary commands remotely.
A remote command injection vulnerability has been discovered in xmonad-contrib.

Summary

A vulnerability in the Xmonad.Hooks.DynamicLog module could allow a malicious website with a specially crafted title to inject commands into the title bar which would be executed when the bar is clicked.

Resolution

All xmonad-contrib users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=x11-wm/xmonad-contrib-0.11.2"

References

[ 1 ] CVE-2013-1436 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1436

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201405-28
style>.gentoo_availability{display:block;}

Concerns

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

Severity: Normal
Title: xmonad-contrib: Arbitrary code execution
Date: May 28, 2014
Bugs: #478288
ID: 201405-28

Synopsis

A remote command injection vulnerability has been discovered in xmonad-contrib.

Background

xmonad-contrib is a set of third party tiling algorithms, configurations, and scripts for xmonad.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 x11-wm/xmonad-contrib < 0.11.2 >= 0.11.2

Impact

===== A remote attacker could possibly execute arbitrary code with the privileges of the process or cause a Denial of Service condition.

Workaround

There is no known workaround at this time.