7.5

CVE-2013-2900

The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not properly handle pathname components composed entirely of . (dot) and whitespace characters, which allows remote attackers to conduct directory traversal attacks via a crafted directory name.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 7.0
Google ≫ Chrome Version <= 29.0.1547.56
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.0
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.1
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.2
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.3
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.4
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.5
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.7
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.8
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.9
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.10
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.11
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.12
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.13
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.14
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.15
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.16
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.17
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.18
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.19
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.20
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.21
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.22
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.23
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.27
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.28
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.29
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.30
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.31
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.32
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.33
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.34
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.35
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.36
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.37
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.38
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.39
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.40
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.41
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.42
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.45
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.46
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.47
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.48
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.49
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.50
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.51
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.52
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.53
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.54
   Microsoft ≫ Windows
Google ≫ Chrome Version 29.0.1547.55
   Microsoft ≫ Windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.55% 0.719
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

http://googlechromereleases.blogspot.com/2013/08/stable-channel-update.html
http://www.debian.org/security/2013/dsa-2741
http://crbug.com/181617
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18381
https://src.chromium.org/viewvc/chrome?revision=200603&view=revision