CVE-2020-1752

HIGH

glibc 2.14-2.31 - Use-After-Free in Tilde Expansion

Title source: llm
STIX 2.1

Description

A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32.

Scores

CVSS v3 7.0
EPSS 0.0013
EPSS Percentile 32.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (10)
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 19.10
debian/debian_linux 10.0
gnu/glibc < 2.32.0
netapp/active_iq_unified_manager 9.5
netapp/h410c_firmware
netapp/hci_management_node
netapp/solidfire
netapp/steelstore_cloud_integrated_storage
Published Apr 30, 2020
Tracked Since Feb 18, 2026