PT-2020-7579 · Libnotify · Libnotify

Published

2020-02-12

·

Updated

2020-08-31

·

CVE-2013-7381

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libnotify versions 1.0.3 and earlier
Description The issue allows remote attackers to execute arbitrary commands via unspecified characters in a call to libnotify.notify(). This is a result of a shell command injection vulnerability, where untrusted input passed into libnotify.notify() could result in the execution of shell commands. The callers of libnotify.notify() may be unaware of this risk.
Recommendations Update to version 1.0.4 or greater. As a temporary workaround, consider validating and sanitizing any user input before passing it to libnotify.notify() to minimize the risk of exploitation. Restrict access to the libnotify.notify() function until the issue is resolved by updating to a secure version.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7381
GHSA-6898-WX94-8JQ8

Affected Products

Libnotify