PT-2014-3151 · Google · Google Chrome

Published

2014-02-20

·

Updated

2014-02-24

·

CVE-2013-6652

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 33.0.1750.117
Description A directory traversal issue in the sandbox allows attackers to bypass intended named-pipe policy restrictions. This is due to either the lack of checks for .. (dot dot) sequences or the lack of use of the ? protection mechanism.
Recommendations For versions prior to 33.0.1750.117, update to version 33.0.1750.117 or later to resolve the issue.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-6652

Affected Products

Google Chrome