CVE-2013-2905
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
21/08/2013
Last modified:
11/04/2025
Description
The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547.57 uses weak permissions under /dev/shm/, which allows attackers to obtain sensitive information via direct access to a POSIX shared-memory file.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | 29.0.1547.56 (including) | |
| cpe:2.3:a:google:chrome:29.0.1547.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.11:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.12:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:29.0.1547.13:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://crbug.com/254159
- http://googlechromereleases.blogspot.com/2013/08/stable-channel-update.html
- http://www.debian.org/security/2013/dsa-2741
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17583
- https://src.chromium.org/viewvc/chrome?revision=209814&view=revision
- http://crbug.com/254159
- http://googlechromereleases.blogspot.com/2013/08/stable-channel-update.html
- http://www.debian.org/security/2013/dsa-2741
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17583
- https://src.chromium.org/viewvc/chrome?revision=209814&view=revision



