Google Chrome before 25.0.1364.97 on Linux, and before 25.0.1364.99 on Mac OS X, does not properly handle pathnames during copy operations, which might make it easier for remote attackers to execute arbitrary programs via unspecified vectors.
References
Link | Resource |
---|---|
http://googlechromereleases.blogspot.com/2013/02/stable-channel-update_21.html | Release Notes Vendor Advisory |
https://code.google.com/p/chromium/issues/detail?id=167840 | Exploit Issue Tracking Mailing List Vendor Advisory |
http://lists.opensuse.org/opensuse-updates/2013-03/msg00045.html | Broken Link Third Party Advisory |
Information
Published : 2013-02-23 13:55
Updated : 2022-11-18 12:03
NVD link : CVE-2013-0895
Mitre link : CVE-2013-0895
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
apple
- mac_os_x
linux
- linux_kernel
- chrome
microsoft
- windows