← Back

CVE-2017-5042

nvd nist
Published: Apr 24, 2017Modified: May 13, 2026

JSON object

Loading...
5.7
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.1 / Impact: 3.6
Source: NVD

Description

Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.

Affected (7)

1 product
Chrome
3 products
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Workstation
1 product
Debian Linux
Configuration A
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Up to 57.0.2987.75
Running on/withPlatform Versions
Apple
Macos
All versions
Linux
Linux Kernel
All versions
Microsoft
Windows
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 57.0.2987.100
Running on/withPlatform Versions
Google
Android
All versions
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.0
Version 6.0
Version 6.0
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 8.0
Version 9.0

References (12)

Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.