Directory traversal vulnerability in sandbox/win/src/named_pipe_dispatcher.cc in Google Chrome before 33.0.1750.117 on Windows allows attackers to bypass intended named-pipe policy restrictions in the sandbox via vectors related to (1) lack of checks for .. (dot dot) sequences or (2) lack of use of the \\?\ protection mechanism.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2014-02-24T02:00:00

Updated: 2014-02-24T02:57:00

Reserved: 2013-11-05T00:00:00


Link: CVE-2013-6652

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-02-24T04:48:09.897

Modified: 2014-02-24T19:20:45.697


Link: CVE-2013-6652

JSON object: View

cve-icon Redhat Information

No data.

CWE