CVE-2010-4833Untrusted Search Path in GTK

Severity
9.3CRITICALNVD
CNA6.9
EPSS
0.5%
top 33.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 6
Latest updateMay 17

Description

Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the current working directory, a different vulnerability than CVE-2010-4831.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDgnome/gtk< 2.24.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r8j5-mmxc-rxw9: Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme2022-05-17
CVEList
CVE-2010-4833: Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme2011-09-06

📋Vendor Advisories

1
Debian
CVE-2010-4833: gtk+2.0 - Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in ...2010
CVE-2010-4833 — Untrusted Search Path in Gnome GTK | cvebase