CVE-2020-12050: SQL Injection
Published Apr 30, 2020
·Updated
SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.
Affected Software
5 affected components
openSUSE Backports SLE=15.0-sp1
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Sqliteodbc Project Sqliteodbc=0.9996
Event History
Apr 30, 2020
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
Description
Frequently Asked Questions
1
What is CVE-2020-12050?
CVE-2020-12050 is a vulnerability in SQLiteODBC 0.9996, as packaged for certain Linux distributions, that allows for a race condition leading to root privilege escalation.
2
How severe is CVE-2020-12050?
CVE-2020-12050 is rated as high severity with a CVSS score of 7.
3
How can I fix CVE-2020-12050?
To fix CVE-2020-12050, users should update to a patched version of SQLiteODBC provided by the respective Linux distribution.