Lucene search

K
cveMitreCVE-2010-3199
HistorySep 10, 2010 - 8:00 p.m.

CVE-2010-3199

2010-09-1020:00:01
CWE-264
mitre
web.nvd.nist.gov
26
cve-2010-3199
untrusted search path
tortoisesvn
vulnerability
dll hijacking
dwmapi.dll
nvd
remote code execution

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

High

EPSS

0.005

Percentile

76.0%

Untrusted search path vulnerability in TortoiseSVN 1.6.10, Build 19898 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a file that is processed by Tortoise. NOTE: this is only a vulnerability when a file extension is associated with TortoiseProc or TortoiseMerge, which is not the default.

Affected configurations

Nvd
Node
tigristortoisesvnRange1.6.10
OR
tigristortoisesvnMatch0.1
OR
tigristortoisesvnMatch0.2
OR
tigristortoisesvnMatch0.3
OR
tigristortoisesvnMatch0.4
OR
tigristortoisesvnMatch0.5
OR
tigristortoisesvnMatch0.5.1
OR
tigristortoisesvnMatch0.6
OR
tigristortoisesvnMatch0.6.1
OR
tigristortoisesvnMatch0.7
OR
tigristortoisesvnMatch0.8
OR
tigristortoisesvnMatch0.8.1
OR
tigristortoisesvnMatch0.9.1
OR
tigristortoisesvnMatch0.9.2
OR
tigristortoisesvnMatch0.10.0
OR
tigristortoisesvnMatch0.11.0
OR
tigristortoisesvnMatch0.11.2
OR
tigristortoisesvnMatch0.12
OR
tigristortoisesvnMatch0.12.1
OR
tigristortoisesvnMatch0.14
OR
tigristortoisesvnMatch0.15
OR
tigristortoisesvnMatch0.15.1
OR
tigristortoisesvnMatch0.15.2
OR
tigristortoisesvnMatch0.16
OR
tigristortoisesvnMatch0.17
OR
tigristortoisesvnMatch0.18
OR
tigristortoisesvnMatch0.19
OR
tigristortoisesvnMatch0.20
OR
tigristortoisesvnMatch0.20.1
OR
tigristortoisesvnMatch0.20.2
OR
tigristortoisesvnMatch0.21
OR
tigristortoisesvnMatch0.22
OR
tigristortoisesvnMatch0.23
OR
tigristortoisesvnMatch0.24
OR
tigristortoisesvnMatch0.25
OR
tigristortoisesvnMatch0.26
OR
tigristortoisesvnMatch1.0
OR
tigristortoisesvnMatch1.0.1
OR
tigristortoisesvnMatch1.0.2
OR
tigristortoisesvnMatch1.0.3
OR
tigristortoisesvnMatch1.0.4
OR
tigristortoisesvnMatch1.0.5
OR
tigristortoisesvnMatch1.0.6
OR
tigristortoisesvnMatch1.0.7
OR
tigristortoisesvnMatch1.0.8
OR
tigristortoisesvnMatch1.1.0
OR
tigristortoisesvnMatch1.1.0rc1
OR
tigristortoisesvnMatch1.1.0rc2
OR
tigristortoisesvnMatch1.1.1
OR
tigristortoisesvnMatch1.1.2
OR
tigristortoisesvnMatch1.1.3
OR
tigristortoisesvnMatch1.1.4
OR
tigristortoisesvnMatch1.1.5
OR
tigristortoisesvnMatch1.1.6
OR
tigristortoisesvnMatch1.1.7
OR
tigristortoisesvnMatch1.2.0
OR
tigristortoisesvnMatch1.2.1
OR
tigristortoisesvnMatch1.2.2
OR
tigristortoisesvnMatch1.2.3
OR
tigristortoisesvnMatch1.2.4
OR
tigristortoisesvnMatch1.2.5
OR
tigristortoisesvnMatch1.2.6
OR
tigristortoisesvnMatch1.3.0
OR
tigristortoisesvnMatch1.3.1
OR
tigristortoisesvnMatch1.3.2
OR
tigristortoisesvnMatch1.3.3
OR
tigristortoisesvnMatch1.3.4
OR
tigristortoisesvnMatch1.3.5
OR
tigristortoisesvnMatch1.4.0
OR
tigristortoisesvnMatch1.4.0rc1
OR
tigristortoisesvnMatch1.4.1
OR
tigristortoisesvnMatch1.4.2
OR
tigristortoisesvnMatch1.4.3
OR
tigristortoisesvnMatch1.4.4
OR
tigristortoisesvnMatch1.4.5
OR
tigristortoisesvnMatch1.4.6
OR
tigristortoisesvnMatch1.4.7
OR
tigristortoisesvnMatch1.4.8
OR
tigristortoisesvnMatch1.5.0
OR
tigristortoisesvnMatch1.5.0alpha1
OR
tigristortoisesvnMatch1.5.0beta1
OR
tigristortoisesvnMatch1.5.0rc1
OR
tigristortoisesvnMatch1.5.0rc2
OR
tigristortoisesvnMatch1.5.0rc3
OR
tigristortoisesvnMatch1.5.1
OR
tigristortoisesvnMatch1.5.2
OR
tigristortoisesvnMatch1.5.3
OR
tigristortoisesvnMatch1.5.4
OR
tigristortoisesvnMatch1.5.5
OR
tigristortoisesvnMatch1.5.6
OR
tigristortoisesvnMatch1.5.7
OR
tigristortoisesvnMatch1.5.8
OR
tigristortoisesvnMatch1.5.9
OR
tigristortoisesvnMatch1.5.10
OR
tigristortoisesvnMatch1.6.0
OR
tigristortoisesvnMatch1.6.3
OR
tigristortoisesvnMatch1.6.4
OR
tigristortoisesvnMatch1.6.5
OR
tigristortoisesvnMatch1.6.6
VendorProductVersionCPE
tigristortoisesvn0.4cpe:/a:tigris:tortoisesvn:0.4:::
tigristortoisesvn1.4.0cpe:/a:tigris:tortoisesvn:1.4.0:::
tigristortoisesvn0.16cpe:/a:tigris:tortoisesvn:0.16:::
tigristortoisesvn1.0.4cpe:/a:tigris:tortoisesvn:1.0.4:::
tigristortoisesvn0.6cpe:/a:tigris:tortoisesvn:0.6:::
tigristortoisesvn0.21cpe:/a:tigris:tortoisesvn:0.21:::
tigristortoisesvn1.5.8cpe:/a:tigris:tortoisesvn:1.5.8:::
tigristortoisesvn1.0.3cpe:/a:tigris:tortoisesvn:1.0.3:::
tigristortoisesvn1.1.1cpe:/a:tigris:tortoisesvn:1.1.1:::
tigristortoisesvn1.4.2cpe:/a:tigris:tortoisesvn:1.4.2:::
Rows per page:
1-10 of 991

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

High

EPSS

0.005

Percentile

76.0%