CVE-2020-1752
published 2020-04-30CVE-2020-1752: A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing…
PriorityP431high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
EPSS
0.53%
41.9th percentile
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | glibc | < glibc 2.30-3 (bookworm) | glibc 2.30-3 (bookworm) |
| flutterchina | dio | >= 0 < 5.0.0 | 5.0.0 |
| gnu | glibc | < 2.32.0 | 2.32.0 |
| gnu | glibc | >= 0 < 2.30-3 | 2.30-3 |
| gnu | glibc | >= 0 < 2.30-3 | 2.30-3 |
| gnu | glibc | >= 0 < 2.30-3 | 2.30-3 |
| gnu | glibc | >= 0 < 2.30-3 | 2.30-3 |
| gnu | glibc | >= 0 < 2.23-0ubuntu11.2 | 2.23-0ubuntu11.2 |
| gnu | glibc | >= 0 < 2.27-3ubuntu1.2 | 2.27-3ubuntu1.2 |
| gnu_libc | glibc | — | — |
| gnu_libc | glibc | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_glibc_2.28-12_on_cbl_mariner_1.0 | — | — |
| netapp | active_iq_unified_manager | >= 9.5 | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
ghsa6.1MEDIUM
osv7.0HIGH
vendor_debian7.0HIGH
vendor_msrc7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
dio vulnerable to CRLF injection with HTTP method string
ghsa·2023-03-21·CVSS 6.1
CVE-2021-31402 [MEDIUM] CWE-93 dio vulnerable to CRLF injection with HTTP method string
dio vulnerable to CRLF injection with HTTP method string
### Impact
The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.
### Patches
The vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0.
### Workarounds
Cherry-pick the commit to your own fork can resolves the vulberability too.
### References
- https://nvd.nist.gov/vuln/detail/CVE-2021-31402
- https://osv.dev/GHSA-jwpw-q68h-r678
- https://github.com/cfug/dio/issues/1130
- https://github.com/cfug/dio/issues/1752
GHSA
GHSA-8x3m-4qgh-829r: A use-after-free vulnerability introduced in glibc upstream version 2
ghsa_unreviewed·2022-05-24
CVE-2020-1752 [MEDIUM] CWE-416 GHSA-8x3m-4qgh-829r: A use-after-free vulnerability introduced in glibc upstream version 2
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32.
OSV
glibc vulnerabilities
osv·2020-07-06·CVSS 5.9
CVE-2017-12133 [MEDIUM] glibc vulnerabilities
glibc vulnerabilities
Florian Weimer discovered that the GNU C Library incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
the GNU C Library to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-12133)
It was discovered that the GNU C Library incorrectly handled certain
SSE2-optimized memmove operations. A remote attacker could use this issue
to cause the GNU C Library to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-18269)
It was discovered that the GNU C Library incorrectly handled certain
pathname operations. A remote attacker could use this issue to cause the
GNU C Library to cras
OSV
CVE-2020-1752: A use-after-free vulnerability introduced in glibc upstream version 2
osv·2020-04-30·CVSS 7.0
CVE-2020-1752 [HIGH] CVE-2020-1752: A use-after-free vulnerability introduced in glibc upstream version 2
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
CISA ICS
Siemens SIMATIC S7-1500 TM MFP BIOS
cisa_ics·2023-06-15·CVSS 5.9
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP BIOS
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP BIOS
Release DateJune 15, 2023
Alert CodeICSA-23-166-10
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Improper Input Validation, Out-of-bounds Read, Use After Free, Out-of-bounds Write, Infinite Loop, Reachable Assertion, Off-by-one Error, Incorrect Default Permissions, Double Fr
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2020-07-06·CVSS 5.9
CVE-2017-12133 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
Florian Weimer discovered that the GNU C Library incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
the GNU C Library to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-12133)
It was discovered that the GNU C Library incorrectly handled certain
SSE2-optimized memmove operations. A remote attacker could use this issue
to cause the GNU C Library to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-18269)
It was discovered that the GNU C Library incorrectly handled certain
pathname operati
Microsoft
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid usern
vendor_msrc·2020-04-14·CVSS 7.0
CVE-2020-1752 [HIGH] CWE-416 A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid usern
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that when processed by the glob function would potentially lead to arbitrary code execution. This was fixed in version 2.32.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the dis
Red Hat
glibc: use-after-free in glob() function when expanding ~user
vendor_redhat·2020-01-17·CVSS 7.0
CVE-2020-1752 [HIGH] CWE-416 glibc: use-after-free in glob() function when expanding ~user
glibc: use-after-free in glob() function when expanding ~user
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32.
A use-after-free vulnerability was found in glibc in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed
Debian
CVE-2020-1752: glibc - A use-after-free vulnerability introduced in glibc upstream version 2.14 was fou...
vendor_debian·2020·CVSS 7.0
CVE-2020-1752 [HIGH] CVE-2020-1752: glibc - A use-after-free vulnerability introduced in glibc upstream version 2.14 was fou...
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32.
Scope: local
bookworm: resolved (fixed in 2.30-3)
bullseye: resolved (fixed in 2.30-3)
forky: resolved (fixed in 2.30-3)
sid: resolved (fixed in 2.30-3)
trixie: resolved (fixed in 2.30-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27752 ImageMagick: heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h
bugzilla·2020-11-03·CVSS 6.1
CVE-2020-27752 [MEDIUM] CVE-2020-27752 ImageMagick: heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h
CVE-2020-27752 ImageMagick: heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h
In ImageMagick, there is a heap-buffer-overflow at MagickCore/quantum-private.h:227 in PopShortPixel.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1752
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/a9d563d3d73874312080d30dc4ba07cecad56192
Discussion:
Acknowledgments:
Name: Suhwan Song (Seoul National University)
---
This looks like the fix for CVE-2020-25664 was an incomplete fix hence the second reproducer which triggers the same thing via the same code path after the patch was applied.
---
Statement:
This flaw is out of support scope for Red Hat Enterprise Linux 5, 6, and 7. Inkscape is not affected because it no longer uses a bundled Imag
Bugzilla
CVE-2020-2115 jenkins-nUnit-plugin: XML parser not configured to prevent XEE
bugzilla·2020-03-31·CVSS 8.8
CVE-2020-2115 [HIGH] CVE-2020-2115 jenkins-nUnit-plugin: XML parser not configured to prevent XEE
CVE-2020-2115 jenkins-nUnit-plugin: XML parser not configured to prevent XEE
A vulnerability was found in Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
Reference:
http://www.openwall.com/lists/oss-security/2020/02/12/3
Discussion:
External References:
https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1752
---
I don't think, this affects the package https://apps.fedoraproject.org/packages/nunit or https://apps.fedoraproject.org/packages/nunit2
If I understand correctly, this security issue is in a plugin of Jenkins, which includes NUnit in Jenkins.
I have never heard about NUnit Plugin 0.25 before.
https://plugins.jenkins.io/nunit/
"This plugin makes it possible to import NUnit reports from each build in
Bugzilla
CVE-2020-1752 glibc: use-after-free in glob() function when expanding ~user [fedora-all]
bugzilla·2020-03-09·CVSS 7.0
CVE-2020-1752 [HIGH] CVE-2020-1752 glibc: use-after-free in glob() function when expanding ~user [fedora-all]
CVE-2020-1752 glibc: use-after-free in glob() function when expanding ~user [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
Bugzilla
CVE-2020-10029 glibc: stack corruption from crafted input in cosl, sinl, sincosl, and tanl functions
bugzilla·2020-03-05·CVSS 5.5
CVE-2020-10029 [MEDIUM] CVE-2020-10029 glibc: stack corruption from crafted input in cosl, sinl, sincosl, and tanl functions
CVE-2020-10029 glibc: stack corruption from crafted input in cosl, sinl, sincosl, and tanl functions
The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.
Reference:
https://sourceware.org/bugzilla/show_bug.cgi?id=25487
Upstream commit:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commit;h=9333498794cde1d5cca518badf79533a24114b6f
Discussion:
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1810671]
---
There's an issue in __ieee754_rem_pio2l() function, where it doesn't validate correctly
Bugzilla
CVE-2020-1752 glibc: use-after-free in glob() function when expanding ~user
bugzilla·2020-03-05·CVSS 7.0
CVE-2020-1752 [HIGH] CVE-2020-1752 glibc: use-after-free in glob() function when expanding ~user
CVE-2020-1752 glibc: use-after-free in glob() function when expanding ~user
It was found a use after free in glob function of glibc when expanding ~user.
Reference:
https://sourceware.org/bugzilla/show_bug.cgi?id=25414
Upstream commit:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=ddc650e9b3dc916eab417ce9f79e67337b05035c
Discussion:
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1811586]
---
Both glibc and gnulib share the same vulnerable code in glob.c.
Generally speaking, function glob_use_alloca() is used to determine whether an object can be allocated on the stack or not:
```
if (glob_use_alloca(alloca_used, size))
/* use stack */
else
/* use malloc */
```
glob_use_alloca() leverages __libc_use_alloca() to implement the actual check. The key differ
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1752https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2022/10/msg00021.htmlhttps://security.gentoo.org/glsa/202101-20https://security.netapp.com/advisory/ntap-20200511-0005/https://sourceware.org/bugzilla/show_bug.cgi?id=25414https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=ddc650e9b3dc916eab417ce9f79e67337b05035chttps://usn.ubuntu.com/4416-1/https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1752https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2022/10/msg00021.htmlhttps://security.gentoo.org/glsa/202101-20https://security.netapp.com/advisory/ntap-20200511-0005/https://sourceware.org/bugzilla/show_bug.cgi?id=25414https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=ddc650e9b3dc916eab417ce9f79e67337b05035chttps://usn.ubuntu.com/4416-1/
2020-04-30
Published