CVE Database
/

CVE-2017-5042

Back to search

CVE-2017-5042

Published: Apr 24, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.

VendorProductVersions

n/a

Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android

affected
Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android

References

GLSA-201704-02
vendor-advisory
x_refsource_GENTOO
https://crbug.com/671932
x_refsource_CONFIRM
DSA-3810
vendor-advisory
x_refsource_DEBIAN
96767
vdb-entry
x_refsource_BID
RHSA-2017:0499
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now