CVE-2010-3199

Description

Untrusted search path vulnerability in TortoiseSVN 1.6.10, Build 19898 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a file that is processed by Tortoise. NOTE: this is only a vulnerability when a file extension is associated with TortoiseProc or TortoiseMerge, which is not the default.

Software From Fixed in
tigris / tortoisesvn 0.19 0.19.x
tigris / tortoisesvn 1.5.0-beta1 1.5.0-beta1.x
tigris / tortoisesvn 1.5.10 1.5.10.x
tigris / tortoisesvn 0.20.1 0.20.1.x
tigris / tortoisesvn 0.12 0.12.x
tigris / tortoisesvn 0.8.1 0.8.1.x
tigris / tortoisesvn 1.6.4 1.6.4.x
tigris / tortoisesvn 1.1.6 1.1.6.x
tigris / tortoisesvn 1.0.6 1.0.6.x
tigris / tortoisesvn 0.9.2 0.9.2.x
tigris / tortoisesvn 1.4.0-rc1 1.4.0-rc1.x
tigris / tortoisesvn 1.3.3 1.3.3.x
tigris / tortoisesvn 0.23 0.23.x
tigris / tortoisesvn 1.1.0-rc1 1.1.0-rc1.x
tigris / tortoisesvn 1.5.5 1.5.5.x
tigris / tortoisesvn 1.3.5 1.3.5.x
tigris / tortoisesvn 1.2.5 1.2.5.x
tigris / tortoisesvn 0.22 0.22.x
tigris / tortoisesvn 0.5 0.5.x
tigris / tortoisesvn 0.21 0.21.x
tigris / tortoisesvn - 1.6.10.x
tigris / tortoisesvn 1.1.1 1.1.1.x
tigris / tortoisesvn 1.5.0-alpha1 1.5.0-alpha1.x
tigris / tortoisesvn 1.2.4 1.2.4.x
tigris / tortoisesvn 0.3 0.3.x
tigris / tortoisesvn 1.6.3 1.6.3.x
tigris / tortoisesvn 0.1 0.1.x
tigris / tortoisesvn 1.5.3 1.5.3.x
tigris / tortoisesvn 0.6 0.6.x
tigris / tortoisesvn 0.17 0.17.x
tigris / tortoisesvn 1.3.1 1.3.1.x
tigris / tortoisesvn 1.5.8 1.5.8.x
tigris / tortoisesvn 1.4.1 1.4.1.x
tigris / tortoisesvn 0.16 0.16.x
tigris / tortoisesvn 1.0.8 1.0.8.x
tigris / tortoisesvn 1.5.9 1.5.9.x
tigris / tortoisesvn 1.2.2 1.2.2.x
tigris / tortoisesvn 1.6.0 1.6.0.x
tigris / tortoisesvn 0.11.2 0.11.2.x
tigris / tortoisesvn 1.5.0-rc1 1.5.0-rc1.x
tigris / tortoisesvn 0.10.0 0.10.0.x
tigris / tortoisesvn 1.5.6 1.5.6.x
tigris / tortoisesvn 0.15.2 0.15.2.x
tigris / tortoisesvn 1.4.0 1.4.0.x
tigris / tortoisesvn 1.0.7 1.0.7.x
tigris / tortoisesvn 0.18 0.18.x
tigris / tortoisesvn 0.8 0.8.x
tigris / tortoisesvn 1.2.1 1.2.1.x
tigris / tortoisesvn 1.4.5 1.4.5.x
tigris / tortoisesvn 1.4.8 1.4.8.x
tigris / tortoisesvn 0.26 0.26.x
tigris / tortoisesvn 1.0.5 1.0.5.x
tigris / tortoisesvn 1.6.6 1.6.6.x
tigris / tortoisesvn 1.0 1.0.x
tigris / tortoisesvn 1.3.4 1.3.4.x
tigris / tortoisesvn 1.1.0 1.1.0.x
tigris / tortoisesvn 1.5.1 1.5.1.x
tigris / tortoisesvn 1.1.3 1.1.3.x
tigris / tortoisesvn 1.4.3 1.4.3.x
tigris / tortoisesvn 1.1.5 1.1.5.x
tigris / tortoisesvn 1.5.0 1.5.0.x
tigris / tortoisesvn 1.5.4 1.5.4.x
tigris / tortoisesvn 1.0.3 1.0.3.x
tigris / tortoisesvn 1.4.2 1.4.2.x
tigris / tortoisesvn 0.20 0.20.x
tigris / tortoisesvn 0.2 0.2.x
tigris / tortoisesvn 1.3.0 1.3.0.x
tigris / tortoisesvn 0.24 0.24.x
tigris / tortoisesvn 0.25 0.25.x
tigris / tortoisesvn 0.15 0.15.x
tigris / tortoisesvn 1.5.0-rc3 1.5.0-rc3.x
tigris / tortoisesvn 1.4.4 1.4.4.x
tigris / tortoisesvn 1.1.0-rc2 1.1.0-rc2.x
tigris / tortoisesvn 1.0.2 1.0.2.x
tigris / tortoisesvn 0.14 0.14.x
tigris / tortoisesvn 1.1.4 1.1.4.x
tigris / tortoisesvn 1.4.6 1.4.6.x
tigris / tortoisesvn 1.4.7 1.4.7.x
tigris / tortoisesvn 1.2.0 1.2.0.x
tigris / tortoisesvn 1.0.1 1.0.1.x
tigris / tortoisesvn 1.0.4 1.0.4.x
tigris / tortoisesvn 0.6.1 0.6.1.x
tigris / tortoisesvn 0.7 0.7.x
tigris / tortoisesvn 0.15.1 0.15.1.x
tigris / tortoisesvn 0.12.1 0.12.1.x
tigris / tortoisesvn 1.1.7 1.1.7.x
tigris / tortoisesvn 0.9.1 0.9.1.x
tigris / tortoisesvn 0.4 0.4.x
tigris / tortoisesvn 1.5.0-rc2 1.5.0-rc2.x
tigris / tortoisesvn 1.5.7 1.5.7.x
tigris / tortoisesvn 1.2.6 1.2.6.x
tigris / tortoisesvn 1.5.2 1.5.2.x
tigris / tortoisesvn 1.2.3 1.2.3.x
tigris / tortoisesvn 1.6.5 1.6.5.x
tigris / tortoisesvn 0.5.1 0.5.1.x
tigris / tortoisesvn 0.20.2 0.20.2.x
tigris / tortoisesvn 1.3.2 1.3.2.x
tigris / tortoisesvn 0.11.0 0.11.0.x
tigris / tortoisesvn 1.1.2 1.1.2.x