ZeroHour

CVE-2020-1752

CVSS 3.1
7.0 high
EPSS
<1%p43
Published
()
Modified
Description

A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32.

Vendors
gnucanonicalnetappdebian
Products
glibc, ubuntu linux, active iq unified manager, hci management node, solidfire, steelstore cloud integrated storage, h410c firmware, debian linux
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.