CVE-2010-4833: Critical severity gtk vulnerability
Untrusted search path vulnerability in modules/engines/ms-windows/xptheme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the current working directory, a different vulnerability than CVE-2010-4831.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4833?
CVE-2010-4833 is classified as a high-severity vulnerability due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2010-4833?
To mitigate CVE-2010-4833, upgrade to GTK+ version 2.24.0 or later, which resolves the untrusted search path vulnerability.
Who is affected by CVE-2010-4833?
CVE-2010-4833 affects local users utilizing GTK+ versions prior to 2.24.0, as they may exploit the untrusted search path vulnerability.
What kind of attack can occur due to CVE-2010-4833?
An attacker could place a rogue uxtheme.dll file in the current working directory, leading to privilege escalation.
Is CVE-2010-4833 a remote attack vulnerability?
No, CVE-2010-4833 is a local attack vulnerability, requiring access to the system where the affected GTK+ version is installed.