Vulnerabilities > CVE-2017-7860 - Out-of-bounds Write vulnerability in Grpc

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
grpc
CWE-787
critical

Summary

Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/ext/client_channel/parse_address.c.

Common Weakness Enumeration (CWE)