Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Use After Free. A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32.
Remediation
Upgrade glibc
to version or higher.
References
CVSS Score
7.0
low severity
-
Attack VectorLocal
-
Attack ComplexityHigh
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2020-1752
- CWE
- CWE-416
- Snyk ID
- SNYK-UBUNTU1604-GLIBC-571389
- Disclosed
- 30 Apr, 2020
- Published
- 07 Mar, 2020