CVE-2017-5042: Medium severity Google Chrome vulnerability
Published Apr 24, 2017
·Updated
Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.
Affected Software
17 affected components
Google Chrome<=57.0.2987.75
Apple macOS
Linux Linux kernel
Microsoft Windows
Google Chrome<=57.0.2987.100
Google Android
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Workstation=6.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
All of the following
Google Chrome<=57.0.2987.75
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
All of the following
Google Chrome<=57.0.2987.100
Google Android
Remediation
Patch Available
Event History
Apr 24, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
Data Sourced
via NVD·11:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5042?
CVE-2017-5042 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-5042?
To fix CVE-2017-5042, update Google Chrome to version 57.0.2987.98 or later.
3
Which versions of Google Chrome are affected by CVE-2017-5042?
CVE-2017-5042 affects Google Chrome versions prior to 57.0.2987.98 for Mac, Windows, and Linux.
4
Can CVE-2017-5042 be exploited remotely?
CVE-2017-5042 requires an attacker to be on the local network segment to exploit the vulnerability.
5
What impact does CVE-2017-5042 have on users?
CVE-2017-5042 allows an attacker to observe plaintext cookies sent to arbitrary URLs.