The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not properly handle pathname components composed entirely of . (dot) and whitespace characters, which allows remote attackers to conduct directory traversal attacks via a crafted directory name.
https://src.chromium.org/viewvc/chrome?revision=200603&view=revision
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18381
http://www.debian.org/security/2013/dsa-2741
http://googlechromereleases.blogspot.com/2013/08/stable-channel-update.html
Published: 2013-08-21
Updated: 2025-04-11
Named Vulnerability: WinVerifyTrust Signature Validation Vulnerability
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 8.1
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Severity: High
EPSS: 0.01567