CVE-2017-5042

Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

22 Apr 2022, 20:28

Type Values Removed Values Added
CPE cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
References (DEBIAN) http://www.debian.org/security/2017/dsa-3810 - (DEBIAN) http://www.debian.org/security/2017/dsa-3810 - Third Party Advisory
References (REDHAT) http://rhn.redhat.com/errata/RHSA-2017-0499.html - (REDHAT) http://rhn.redhat.com/errata/RHSA-2017-0499.html - Third Party Advisory
References (BID) http://www.securityfocus.com/bid/96767 - Third Party Advisory, VDB Entry (BID) http://www.securityfocus.com/bid/96767 - Broken Link
References (GENTOO) https://security.gentoo.org/glsa/201704-02 - (GENTOO) https://security.gentoo.org/glsa/201704-02 - Third Party Advisory
References (CONFIRM) https://crbug.com/671932 - Issue Tracking, Patch (CONFIRM) https://crbug.com/671932 - Issue Tracking, Patch, Vendor Advisory

08 Sep 2021, 17:19

Type Values Removed Values Added
CPE cpe:2.3:o:apple:mac_os:-:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

Information

Published : 2017-04-24 23:59

Updated : 2024-02-04 19:11


NVD link : CVE-2017-5042

Mitre link : CVE-2017-5042

CVE.ORG link : CVE-2017-5042


JSON object : View

Products Affected

redhat

  • enterprise_linux_server
  • enterprise_linux_workstation
  • enterprise_linux_desktop

apple

  • macos

microsoft

  • windows

google

  • chrome
  • android

debian

  • debian_linux

linux

  • linux_kernel
CWE
CWE-311

Missing Encryption of Sensitive Data