Upstream information

CVE-2017-5042 at MITRE

Description

Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.

SUSE information

CVSS v2 Scores
  National Vulnerability Database
Base Score 3.29
Vector AV:A/AC:L/Au:N/C:P/I:N/A:N
Access Vector Adjacent Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
CVSS v3 Scores
  National Vulnerability Database
Base Score 5.7
Vector AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Access Vector Adjacent Network
Access Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Impact High
Integrity Impact None
Availability Impact None
SUSE Bugzilla entries: 1028848 [RESOLVED / FIXED], 1028875 [RESOLVED / DUPLICATE]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE Leap 42.1
  • chromedriver >= 57.0.2987.98-105.2
  • chromedriver-debuginfo >= 57.0.2987.98-105.2
  • chromium >= 57.0.2987.98-105.2
  • chromium-debuginfo >= 57.0.2987.98-105.2
  • chromium-debugsource >= 57.0.2987.98-105.2
Patchnames:
openSUSE-2017-353
openSUSE Leap 42.2
  • chromedriver >= 57.0.2987.98-105.2
  • chromedriver-debuginfo >= 57.0.2987.98-105.2
  • chromium >= 57.0.2987.98-105.2
  • chromium-debuginfo >= 57.0.2987.98-105.2
  • chromium-debugsource >= 57.0.2987.98-105.2
Patchnames:
openSUSE-2017-353