Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the current working directory, a different vulnerability than CVE-2010-4831.
References
Link | Resource |
---|---|
http://git.gnome.org/browse/gtk+/commit/modules/engines/ms-windows/xp_theme.c?h=gtk-2-24&id=d6e11a97e318158f5d210a0476870dfe14ed95e6 | Patch |
http://secunia.com/advisories/45815 | Broken Link |
http://www.securityfocus.com/bid/49449 | Broken Link Third Party Advisory VDB Entry |
http://git.gnome.org/browse/gtk+/commit/modules/engines/ms-windows/xp_theme.c?h=gtk-2-24&id=d6e11a97e318158f5d210a0476870dfe14ed95e6 | Patch |
http://secunia.com/advisories/45815 | Broken Link |
http://www.securityfocus.com/bid/49449 | Broken Link Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 01:21
Type | Values Removed | Values Added |
---|---|---|
References | () http://git.gnome.org/browse/gtk+/commit/modules/engines/ms-windows/xp_theme.c?h=gtk-2-24&id=d6e11a97e318158f5d210a0476870dfe14ed95e6 - Patch | |
References | () http://secunia.com/advisories/45815 - Broken Link | |
References | () http://www.securityfocus.com/bid/49449 - Broken Link, Third Party Advisory, VDB Entry |
03 Aug 2023, 17:21
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-426 | |
First Time |
Gnome gtk
Gnome |
|
References | (CONFIRM) http://git.gnome.org/browse/gtk+/commit/modules/engines/ms-windows/xp_theme.c?h=gtk-2-24&id=d6e11a97e318158f5d210a0476870dfe14ed95e6 - Patch | |
References | (BID) http://www.securityfocus.com/bid/49449 - Broken Link, Third Party Advisory, VDB Entry | |
References | (SECUNIA) http://secunia.com/advisories/45815 - Broken Link | |
CPE | cpe:2.3:a:gtk:gtk\+:2.10.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.3.13:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.10.13:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.23.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.16.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.2.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.23.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.2.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.19.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.10.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.10.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.12.11:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.1.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.18.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.15.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.6.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.14.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.10.10:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.3.11:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.13.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.21.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.19.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.14.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.14.7:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.10.11:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.13.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.15.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.10.8:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.3.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.10.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.1.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.14.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.19.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.16:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.3.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.23.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.7.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.5.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.14:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.17.10:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.6.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.2.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.2.8:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.1.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.17.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.18.7:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.0.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.2.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.11.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.3.10:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.2.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.12.8:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.0.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.12.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.20:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.19.7:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.21.8:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.0.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.10.14:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.16.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.11.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.14.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.0.7:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.9:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.15.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.18.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.2.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.15.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.2.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.14.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.5.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.20.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.11.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.6.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.10:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.7:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.22.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.6.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.11.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.18.9:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.14:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.18:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.21.7:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.16.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.7:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.1.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.8:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.0.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.11:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.17.7:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.8:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.0.8:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.17.8:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.12.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.17.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.1.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.6.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.22.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.5.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.19.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.17.11:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.7.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.12:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.7.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.9.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.17.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.1.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.15:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.21.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.13.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.17.9:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.14.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.13.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.6.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.15.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.19:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.10:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.9.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.3.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.13.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.2.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.3.15:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.0.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.12.7:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.17.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.10.12:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.21.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.21.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.5.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.16.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.16.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.16.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.19.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.12.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.6.8:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.12.12:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.7.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.6.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.5.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.12.10:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.12.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.3.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.21.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.6.10:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.9.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.9:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.11.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.2.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.20.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.3.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.6.9:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.11.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.2.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.2.10:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.14.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.5.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.19.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.7.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.2.9:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.5:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.10.7:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.10.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.13.7:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.2.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.12:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.17.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.16.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.13:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.12.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.3.12:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.12.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.18.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.15.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.17.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.18.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.2.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.10.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.5.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.1.15:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.0.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.7.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.11:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.18.8:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.10.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.1.12:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.2.7:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.10.9:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.18.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.13.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.3.9:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.13.2:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.3.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.23.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.18.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.0.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.6.7:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.19.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.13:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.0.9:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.12.9:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.8.17:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.18.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.4.1:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.9.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.12.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.21.0:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.21.6:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.3.4:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.17.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.11.3:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:1.3.14:*:*:*:*:*:*:* cpe:2.3:a:gtk:gtk\+:2.9.1:*:*:*:*:*:*:* |
cpe:2.3:a:gnome:gtk:*:*:*:*:*:*:*:* |
Information
Published : 2011-09-06 15:55
Updated : 2024-11-21 01:21
NVD link : CVE-2010-4833
Mitre link : CVE-2010-4833
CVE.ORG link : CVE-2010-4833
JSON object : View
Products Affected
gnome
- gtk
CWE
CWE-426
Untrusted Search Path