CVE-2017-7861: Critical severity gRPC gRPC vulnerability
Published Apr 14, 2017
·Updated
Google gRPC before 2017-02-22 has an out-of-bounds write related to the gprfree function in core/lib/support/alloc.c.
Affected Software
1 affected component
gRPC gRPC<=1.1.2
Remediation
Patch Available
Event History
Apr 14, 2017
CVE Published
via MITRE·04:30 AM
Data Sourced
via MITRE·04:30 AM
Description
Data Sourced
via NVD·04:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7861?
CVE-2017-7861 has a medium severity rating due to the potential for an out-of-bounds write which could lead to application crashes or arbitrary code execution.
2
How do I fix CVE-2017-7861?
To fix CVE-2017-7861, update your gRPC implementation to version 1.1.3 or later.
3
What software is affected by CVE-2017-7861?
CVE-2017-7861 affects versions of gRPC prior to 1.1.3.
4
What type of vulnerability is CVE-2017-7861?
CVE-2017-7861 is an out-of-bounds write vulnerability related to the gpr_free function.
5
When was CVE-2017-7861 disclosed?
CVE-2017-7861 was disclosed on February 22, 2017.