CVE-2017-5042

Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 03:26

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2017-0499.html - () http://rhn.redhat.com/errata/RHSA-2017-0499.html -
References () http://www.debian.org/security/2017/dsa-3810 - () http://www.debian.org/security/2017/dsa-3810 -
References () http://www.securityfocus.com/bid/96767 - () http://www.securityfocus.com/bid/96767 -
References () https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html - () https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html -
References () https://crbug.com/671932 - () https://crbug.com/671932 -
References () https://security.gentoo.org/glsa/201704-02 - () https://security.gentoo.org/glsa/201704-02 -

Information

Published : 2017-04-24 23:59

Updated : 2025-04-20 01:37


NVD link : CVE-2017-5042

Mitre link : CVE-2017-5042

CVE.ORG link : CVE-2017-5042


JSON object : View

Products Affected

redhat

  • enterprise_linux_workstation
  • enterprise_linux_desktop
  • enterprise_linux_server

debian

  • debian_linux

linux

  • linux_kernel

google

  • chrome
  • android

microsoft

  • windows

apple

  • macos
CWE
CWE-311

Missing Encryption of Sensitive Data