CVE-2020-1752
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32.
- CVSS 3.1
- 7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.53% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- gnu/glibc · canonical/ubuntu linux · netapp/active iq unified manager · netapp/hci management node · netapp/solidfire · netapp/steelstore cloud integrated storage · netapp/h410c firmware · debian/debian linux
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1752Issue Tracking, Patch, Third Party Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202101-20Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200511-0005/Third Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=25414Issue Tracking, Patch, Third Party Advisory
- https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=ddc650e9b3dc916eab417ce9f79e67337b05035c
- https://usn.ubuntu.com/4416-1/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1752Issue Tracking, Patch, Third Party Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202101-20Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200511-0005/Third Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=25414Issue Tracking, Patch, Third Party Advisory
- https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=ddc650e9b3dc916eab417ce9f79e67337b05035c
- https://usn.ubuntu.com/4416-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.