CVE-2013-6652
Publication date 24 February 2014
Last updated 24 July 2024
Ubuntu priority
Description
Directory traversal vulnerability in sandbox/win/src/named_pipe_dispatcher.cc in Google Chrome before 33.0.1750.117 on Windows allows attackers to bypass intended named-pipe policy restrictions in the sandbox via vectors related to (1) lack of checks for .. (dot dot) sequences or (2) lack of use of the \\?\ protection mechanism.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| chromium-browser | ||