CVE-2017-5042

Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

07 Nov 2023, 02:48

Type Values Removed Values Added
References (CONFIRM) https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html - Vendor Advisory () https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html -
References (BID) http://www.securityfocus.com/bid/96767 - Broken Link () http://www.securityfocus.com/bid/96767 -
References (CONFIRM) https://crbug.com/671932 - Issue Tracking, Patch, Vendor Advisory () https://crbug.com/671932 -
References (DEBIAN) http://www.debian.org/security/2017/dsa-3810 - Third Party Advisory () http://www.debian.org/security/2017/dsa-3810 -
References (REDHAT) http://rhn.redhat.com/errata/RHSA-2017-0499.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2017-0499.html -
References (GENTOO) https://security.gentoo.org/glsa/201704-02 - Third Party Advisory () https://security.gentoo.org/glsa/201704-02 -

22 Apr 2022, 20:28

Type Values Removed Values Added
CPE cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
First Time Debian debian Linux
Redhat enterprise Linux Desktop
Redhat enterprise Linux Server
Debian
Redhat enterprise Linux Workstation
Redhat
References (DEBIAN) http://www.debian.org/security/2017/dsa-3810 - (DEBIAN) http://www.debian.org/security/2017/dsa-3810 - Third Party Advisory
References (CONFIRM) https://crbug.com/671932 - Issue Tracking, Patch (CONFIRM) https://crbug.com/671932 - Issue Tracking, Patch, Vendor Advisory
References (GENTOO) https://security.gentoo.org/glsa/201704-02 - (GENTOO) https://security.gentoo.org/glsa/201704-02 - Third Party Advisory
References (BID) http://www.securityfocus.com/bid/96767 - Third Party Advisory, VDB Entry (BID) http://www.securityfocus.com/bid/96767 - Broken Link
References (REDHAT) http://rhn.redhat.com/errata/RHSA-2017-0499.html - (REDHAT) http://rhn.redhat.com/errata/RHSA-2017-0499.html - Third Party Advisory

08 Sep 2021, 17:19

Type Values Removed Values Added
CPE cpe:2.3:o:apple:mac_os:-:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

Information

Published : 2017-04-24 23:59

Updated : 2023-12-10 12:01


NVD link : CVE-2017-5042

Mitre link : CVE-2017-5042

CVE.ORG link : CVE-2017-5042


JSON object : View

Products Affected

redhat

  • enterprise_linux_server
  • enterprise_linux_desktop
  • enterprise_linux_workstation

debian

  • debian_linux

apple

  • macos

linux

  • linux_kernel

google

  • chrome
  • android

microsoft

  • windows
CWE
CWE-311

Missing Encryption of Sensitive Data