glibc: use-after-free in glob() function when expanding ~user
Published Apr 30, 2020
7.0
HIGHCVSS 3.1
EPSS 0.53%
Description
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32.
Affected products
-
- Version Affected: versions 2.14 and laterStatusaffectedConstraints-
- Version Fixed: version 2.32StatusaffectedConstraints-
- Version
Configuration 2
- 16.04
- 18.04
- 19.10
Configuration 3
- ≥ 9.5
- n/a
- n/a
- n/a
Configuration 4
- n/a
Configuration 5
- 10.0
No data.
Red Hat Enterprise Linux 8
glibc-0:2.28-127.el8
Fixed · RHSA-2020:4444
Red Hat Enterprise Linux 8
glibc-0:2.28-127.el8
Fixed · RHSA-2020:4444
Red Hat Enterprise Linux 5
glibc
Not affected
Red Hat Enterprise Linux 6
glibc
Not affected
Red Hat Enterprise Linux 7
glibc
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | glibc-0:2.28-127.el8 | Fixed | RHSA-2020:4444 |
| Red Hat Enterprise Linux 8 | glibc-0:2.28-127.el8 | Fixed | RHSA-2020:4444 |
| Red Hat Enterprise Linux 5 | glibc | Not affected | n/a |
| Red Hat Enterprise Linux 6 | glibc | Not affected | n/a |
| Red Hat Enterprise Linux 7 | glibc | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The Red Hat Product Security Team has rated this issue as having Moderate security impact. This flaw did not affect the versions of `glibc` as shipped with Red Hat Enterprise Linux 5 and 6, as the vulnerable code was introduced in a later version of the package. Red Hat Enterprise Linux 7 is approaching the End of Maintenance Support 1 Phase of the support and maintenance life cycle. The flaw is not currently planned to be addressed in future updates of Red Hat Enterprise Linux 7, hence marked as "Will not fix". For further information, please refer to the Red Hat Enterprise Linux Life Cycle and Issue Severity Classification: [1] https://access.redhat.com/support/policy/updates/errata [2] https://access.redhat.com/security/updates/classification
Red Hat mitigation
Avoid the expansion of overly long directory paths.
References (14)
- https://access.redhat.com/security/cve/CVE-2020-1752 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1810718 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1752 Issue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-12583 Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E mailing-list
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-1752
- https://security.gentoo.org/glsa/202101-20 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200511-0005/ Third Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=25414 Issue TrackingPatchThird Party Advisory
- https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=ddc650e9b3dc916eab417ce9f79e67337b05035c
- https://usn.ubuntu.com/4416-1/ vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-1752
Change history (0)
No recorded changes yet.