Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the current working directory, a different vulnerability than CVE-2010-4831.
References
Link | Resource |
---|---|
http://git.gnome.org/browse/gtk+/commit/modules/engines/ms-windows/xp_theme.c?h=gtk-2-24&id=d6e11a97e318158f5d210a0476870dfe14ed95e6 | Patch |
http://secunia.com/advisories/45815 | Broken Link |
http://www.securityfocus.com/bid/49449 | Broken Link Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2011-09-06 15:55
Updated : 2023-08-03 17:21
NVD link : CVE-2010-4833
Mitre link : CVE-2010-4833
CVE.ORG link : CVE-2010-4833
JSON object : View
Products Affected
gnome
- gtk
CWE
CWE-426
Untrusted Search Path