PT-2020-13015 · Sqlite+3 · Sqliteodbc+3

Published

2020-04-30

·

Updated

2024-06-15

·

CVE-2020-12050

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SQLiteODBC version 0.9996
Description The issue is related to a race condition that can lead to root privilege escalation. This occurs because any user can replace a /tmp/sqliteodbc$$ file with new contents, causing the loading of an arbitrary library.
Recommendations For SQLiteODBC version 0.9996, consider restricting access to the /tmp/sqliteodbc$$ file to prevent unauthorized modifications until a patch is available. As a temporary workaround, restrict the loading of arbitrary libraries to minimize the risk of exploitation.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3378
ALT-PU-2020-3462
ALT-PU-2022-2114
CVE-2020-12050
OPENSUSE-SU-2020:0612-1
OPENSUSE-SU-2020:0628-1
OPENSUSE-SU-2020_0628-1
OPENSUSE-SU-2024:11401-1

Affected Products

Alt Linux
Debian
Sqliteodbc
Suse