yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2013-7381
Component Overview
Vulnerability Overview
Name
CVE-2013-7381
Source
NVD (
link
)
Debian (
link
)
Description
libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a call to libnotify.notify.
CWEs
CWE-74
Published Date
Feb 12, 2020
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://www.openwall.com/lists/oss-security/2014/05/13/1
Mailing List
http://www.openwall.com/lists/oss-security/2014/05/15/2
Mailing List
https://github.com/mytrile/node-libnotify/commit/dfe7801d73a0dda10663a0ff3d0ec8b4d5f0d448
Patch
https://nodesecurity.io/advisories/libnotify_potential_command_injection_in_libnotify.notify
Broken Link
http://www.openwall.com/lists/oss-security/2014/05/13/1
Mailing List
http://www.openwall.com/lists/oss-security/2014/05/15/2
Mailing List
https://github.com/mytrile/node-libnotify/commit/dfe7801d73a0dda10663a0ff3d0ec8b4d5f0d448
Patch
https://nodesecurity.io/advisories/libnotify_potential_command_injection_in_libnotify.notify
Broken Link
Analysis
#
Affected Component
Analysis
libnotify
False Positive
Vulnerability Ratings
#
9.8
CVSSv31
7.5
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
libnotify
yocto
kirkstone
0.7.9
Not Affected
libnotify
yocto
master
0.8.8
False Positive