Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-12050. PoCs published by tnpitsecurity.
AI-analyzed exploit summary The repository contains a functional Go exploit for CVE-2020-12050, which leverages a race condition in the sqliteODBC installer script to achieve privilege escalation. The exploit pre-creates hardlinks in /tmp to win the race and inject a malicious ODBC configuration.
Description
SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.
Exploits (1)
The repository contains a functional Go exploit for CVE-2020-12050, which leverages a race condition in the sqliteODBC installer script to achieve privilege escalation. The exploit pre-creates hardlinks in /tmp to win the race and inject a malicious ODBC configuration.
References (9)
Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H