Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the current working directory, a different vulnerability than CVE-2010-4831.
References
Link | Resource |
---|---|
http://git.gnome.org/browse/gtk+/commit/modules/engines/ms-windows/xp_theme.c?h=gtk-2-24&id=d6e11a97e318158f5d210a0476870dfe14ed95e6 | Patch |
http://secunia.com/advisories/45815 | Broken Link |
http://www.securityfocus.com/bid/49449 | Broken Link Third Party Advisory VDB Entry |
http://git.gnome.org/browse/gtk+/commit/modules/engines/ms-windows/xp_theme.c?h=gtk-2-24&id=d6e11a97e318158f5d210a0476870dfe14ed95e6 | Patch |
http://secunia.com/advisories/45815 | Broken Link |
http://www.securityfocus.com/bid/49449 | Broken Link Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 01:21
Type | Values Removed | Values Added |
---|---|---|
References | () http://git.gnome.org/browse/gtk+/commit/modules/engines/ms-windows/xp_theme.c?h=gtk-2-24&id=d6e11a97e318158f5d210a0476870dfe14ed95e6 - Patch | |
References | () http://secunia.com/advisories/45815 - Broken Link | |
References | () http://www.securityfocus.com/bid/49449 - Broken Link, Third Party Advisory, VDB Entry |
Information
Published : 2011-09-06 15:55
Updated : 2024-11-21 01:21
NVD link : CVE-2010-4833
Mitre link : CVE-2010-4833
CVE.ORG link : CVE-2010-4833
JSON object : View
Products Affected
gnome
- gtk
CWE
CWE-426
Untrusted Search Path