CVE-2010-3199
Untrusted search path vulnerability in TortoiseSVN 1.6.10, Build 19898 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a file that is processed by Tortoise. NOTE: this is only a vulnerability when a file extension is associated with TortoiseProc or TortoiseMerge, which is not the default.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3199?
CVE-2010-3199 has a severity rating that indicates it could allow local users and possibly remote attackers to execute arbitrary code.
How do I fix CVE-2010-3199?
To fix CVE-2010-3199, upgrade to a version of TortoiseSVN that is later than 1.6.10.
What versions of TortoiseSVN are affected by CVE-2010-3199?
CVE-2010-3199 affects TortoiseSVN versions up to and including 1.6.10.
What type of attack can be executed through CVE-2010-3199?
CVE-2010-3199 allows for DLL hijacking attacks through a specially crafted dwmapi.dll file.
Who is impacted by CVE-2010-3199?
Both local users and potentially remote attackers can exploit CVE-2010-3199.