CVE-2013-2900
CVE-2013-2900
The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not properly handle pathname components composed entirely of . (dot) and whitespace characters, which allows remote attackers to conduct directory traversal attacks via a crafted directory name.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://crbug.com/181617http://googlechromereleases.blogspot.com/2013/08/stable-channel-update.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18381https://src.chromium.org/viewvc/chrome?revision=200603&view=revisionhttp://www.debian.org/security/2013/dsa-2741