High severity7.0NVD Advisory· Published Apr 30, 2020· Updated Jun 17, 2026
CVE-2020-12050
CVE-2020-12050
Description
SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- SQLiteODBC/SQLiteODBCdescription
- Range: 0.9996
- osv-coords3 versionspkg:rpm/opensuse/sqliteodbc&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/sqliteodbc&distro=openSUSE%20Tumbleweedpkg:rpm/suse/sqliteodbc&distro=SUSE%20Package%20Hub%2015%20SP1
< 0.9996-lp151.3.3.1+ 2 more
- (no CPE)range: < 0.9996-lp151.3.3.1
- (no CPE)range: < 0.9998-1.7
- (no CPE)range: < 0.9996-bp151.4.3.1
Patches
Vulnerability mechanics
References
9- lists.opensuse.org/opensuse-security-announce/2020-05/msg00013.htmlnvdMailing ListThird Party Advisory
- www.ch-werner.de/sqliteodbc/nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- sysdream.com/news/lab/nvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-05/msg00026.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDS5RK7F47BRXHUYRWGMGLYU2GJEVZQA/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PR6B33IGBADGYDBTEEU36OGERER2HOGQ/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXPHBDVB3LAQUQJCZ4WIS3JWM7JFR56X/nvd
- sysdream.com/news/lab/2020-05-25-cve-2020-12050-fedora-red-hat-centos-local-privilege-escalation-through-a-race-condition-in-the-sqliteodbc-installer-script/nvd
News mentions
0No linked articles in our index yet.