CVE-2020-1752: Use After Free
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/glibcto a version that resolves this vulnerability.Fixed in 2.31-13+deb11u11Fixed in 2.31-13+deb11u14Fixed in 2.36-9+deb12u14Fixed in 2.36-9+deb12u7Fixed in 2.41-12+deb13u3Fixed in 2.42-17 - Upgrade
Upgrade
glibcto a version that resolves this vulnerability.Fixed in 2.32
Event History
Frequently Asked Questions
What is CVE-2020-1752?
CVE-2020-1752 is a use-after-free vulnerability in glibc.
How severe is CVE-2020-1752?
CVE-2020-1752 has a severity rating of high (7.0).
What software is affected by CVE-2020-1752?
Ubuntu glibc versions 2.27-3ubuntu1.2, 2.30-0ubuntu2.2, and 2.23-0ubuntu11.2 are affected.
How can I fix CVE-2020-1752 on Ubuntu?
To fix CVE-2020-1752 on Ubuntu, update glibc to versions 2.27-3ubuntu1.2, 2.30-0ubuntu2.2, or 2.23-0ubuntu11.2.
Where can I find more information about CVE-2020-1752?
You can find more information about CVE-2020-1752 on the MITRE CVE website, the Ubuntu Security Notices website, or the NIST NVD website.