Security Advisory

CVE-2013-6652

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-02-24 02:00:00
Last updated 2024-08-06 17:46:22
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Directory traversal vulnerability in sandbox/win/src/named_pipe_dispatcher.cc in Google Chrome before 33.0.1750.117 on Windows allows attackers to bypass intended named-pipe policy restrictions in the sandbox via vectors related to (1) lack of checks for .. (dot dot) sequences or (2) lack of use of the \\?\ protection mechanism.