CVE-2013-2900
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
21/08/2013
Last modified:
11/04/2025
Description
The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not properly handle pathname components composed entirely of . (dot) and whitespace characters, which allows remote attackers to conduct directory traversal attacks via a crafted directory name.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | 29.0.1547.56 (including) | |
| cpe:2.3:a:google:chrome:29.0.1547.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.11:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.12:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.13:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://crbug.com/181617
- http://googlechromereleases.blogspot.com/2013/08/stable-channel-update.html
- http://www.debian.org/security/2013/dsa-2741
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18381
- https://src.chromium.org/viewvc/chrome?revision=200603&view=revision
- http://crbug.com/181617
- http://googlechromereleases.blogspot.com/2013/08/stable-channel-update.html
- http://www.debian.org/security/2013/dsa-2741
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18381
- https://src.chromium.org/viewvc/chrome?revision=200603&view=revision



