← Back

CVE-2013-2900

nvd nist
Published: Aug 21, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not properly handle pathname components composed entirely of . (dot) and whitespace characters, which allows remote attackers to conduct directory traversal attacks via a crafted directory name.

Affected (52)

1 product
Debian Linux
1 product
Chrome
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0
Configuration B
51 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Google
Up to 29.0.1547.56
Version 29.0.1547.0
Version 29.0.1547.10
Version 29.0.1547.11
Version 29.0.1547.12
Version 29.0.1547.13
Version 29.0.1547.14
Version 29.0.1547.15
Version 29.0.1547.16
Version 29.0.1547.17
Version 29.0.1547.18
Version 29.0.1547.19
Version 29.0.1547.1
Version 29.0.1547.20
Version 29.0.1547.21
Version 29.0.1547.22
Version 29.0.1547.23
Version 29.0.1547.27
Version 29.0.1547.28
Version 29.0.1547.29
Version 29.0.1547.2
Version 29.0.1547.30
Version 29.0.1547.31
Version 29.0.1547.32
Version 29.0.1547.33
Version 29.0.1547.34
Version 29.0.1547.35
Version 29.0.1547.36
Version 29.0.1547.37
Version 29.0.1547.38
Version 29.0.1547.39
Version 29.0.1547.3
Version 29.0.1547.40
Version 29.0.1547.41
Version 29.0.1547.42
Version 29.0.1547.45
Version 29.0.1547.46
Version 29.0.1547.47
Version 29.0.1547.48
Version 29.0.1547.49
Version 29.0.1547.4
Version 29.0.1547.50
Version 29.0.1547.51
Version 29.0.1547.52
Version 29.0.1547.53
Version 29.0.1547.54
Version 29.0.1547.55
Version 29.0.1547.5
Version 29.0.1547.7
Version 29.0.1547.8
Version 29.0.1547.9
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (10)

Timeline

No history available yet.