CVE-2017-5042

Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 03:26

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2017-0499.html - () http://rhn.redhat.com/errata/RHSA-2017-0499.html -
References () http://www.debian.org/security/2017/dsa-3810 - () http://www.debian.org/security/2017/dsa-3810 -
References () http://www.securityfocus.com/bid/96767 - () http://www.securityfocus.com/bid/96767 -
References () https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html - () https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html -
References () https://crbug.com/671932 - () https://crbug.com/671932 -
References () https://security.gentoo.org/glsa/201704-02 - () https://security.gentoo.org/glsa/201704-02 -

22 Apr 2022, 20:28

Type Values Removed Values Added
CPE cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
References (DEBIAN) http://www.debian.org/security/2017/dsa-3810 - (DEBIAN) http://www.debian.org/security/2017/dsa-3810 - Third Party Advisory
References (REDHAT) http://rhn.redhat.com/errata/RHSA-2017-0499.html - (REDHAT) http://rhn.redhat.com/errata/RHSA-2017-0499.html - Third Party Advisory
References (BID) http://www.securityfocus.com/bid/96767 - Third Party Advisory, VDB Entry (BID) http://www.securityfocus.com/bid/96767 - Broken Link
References (GENTOO) https://security.gentoo.org/glsa/201704-02 - (GENTOO) https://security.gentoo.org/glsa/201704-02 - Third Party Advisory
References (CONFIRM) https://crbug.com/671932 - Issue Tracking, Patch (CONFIRM) https://crbug.com/671932 - Issue Tracking, Patch, Vendor Advisory

08 Sep 2021, 17:19

Type Values Removed Values Added
CPE cpe:2.3:o:apple:mac_os:-:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

Information

Published : 2017-04-24 23:59

Updated : 2024-11-21 03:26


NVD link : CVE-2017-5042

Mitre link : CVE-2017-5042

CVE.ORG link : CVE-2017-5042


JSON object : View

Products Affected

google

  • chrome
  • android

redhat

  • enterprise_linux_desktop
  • enterprise_linux_server
  • enterprise_linux_workstation

microsoft

  • windows

linux

  • linux_kernel

apple

  • macos

debian

  • debian_linux
CWE
CWE-311

Missing Encryption of Sensitive Data