CVE-2016-1671

Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, which allows attackers to conduct directory traversal attacks via a file: URL, related to net/base/escape.cc and net/base/filename_util.cc.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:46

Type Values Removed Values Added
References () http://googlechromereleases.blogspot.com/2016/05/stable-channel-update.html - () http://googlechromereleases.blogspot.com/2016/05/stable-channel-update.html -
References () http://www.securityfocus.com/bid/90584 - () http://www.securityfocus.com/bid/90584 -
References () http://www.securitytracker.com/id/1035872 - () http://www.securitytracker.com/id/1035872 -
References () https://codereview.chromium.org/1704163003/ - () https://codereview.chromium.org/1704163003/ -
References () https://crbug.com/586657 - () https://crbug.com/586657 -
References () https://groups.google.com/a/chromium.org/forum/message/raw?msg=chromium-reviews/UkMGbbnTDW8/A4g-6YkfBAAJ - () https://groups.google.com/a/chromium.org/forum/message/raw?msg=chromium-reviews/UkMGbbnTDW8/A4g-6YkfBAAJ -
References () https://security.gentoo.org/glsa/201605-02 - () https://security.gentoo.org/glsa/201605-02 -

07 Nov 2023, 02:30

Type Values Removed Values Added
References (CONFIRM) http://googlechromereleases.blogspot.com/2016/05/stable-channel-update.html - Vendor Advisory () http://googlechromereleases.blogspot.com/2016/05/stable-channel-update.html -
References (MLIST) https://groups.google.com/a/chromium.org/forum/message/raw?msg=chromium-reviews/UkMGbbnTDW8/A4g-6YkfBAAJ - () https://groups.google.com/a/chromium.org/forum/message/raw?msg=chromium-reviews/UkMGbbnTDW8/A4g-6YkfBAAJ -
References (GENTOO) https://security.gentoo.org/glsa/201605-02 - () https://security.gentoo.org/glsa/201605-02 -
References (CONFIRM) https://crbug.com/586657 - () https://crbug.com/586657 -
References (SECTRACK) http://www.securitytracker.com/id/1035872 - () http://www.securitytracker.com/id/1035872 -
References (CONFIRM) https://codereview.chromium.org/1704163003/ - () https://codereview.chromium.org/1704163003/ -
References (BID) http://www.securityfocus.com/bid/90584 - () http://www.securityfocus.com/bid/90584 -

Information

Published : 2016-05-14 21:59

Updated : 2024-11-21 02:46


NVD link : CVE-2016-1671

Mitre link : CVE-2016-1671

CVE.ORG link : CVE-2016-1671


JSON object : View

Products Affected

google

  • chrome
  • android
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')