mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 01:31:01 +00:00
20 lines
929 B
Markdown
20 lines
929 B
Markdown
![]() |
### [CVE-2020-12050](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12050)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://bugzilla.redhat.com/show_bug.cgi?id=1825762
|
||
|
- https://sysdream.com/news/lab/
|
||
|
- https://sysdream.com/news/lab/2020-05-25-cve-2020-12050-fedora-red-hat-centos-local-privilege-escalation-through-a-race-condition-in-the-sqliteodbc-installer-script/
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/tnpitsecurity/CVEs
|
||
|
|