CVE-2017-9431: Buffer Overflow
Published Jun 5, 2017
·Updated
Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.
Affected Software
1 affected component
gRPC gRPC<=1.2.2
Remediation
Patch Available
Patch Available
Event History
Jun 5, 2017
CVE Published
via MITRE·02:47 AM
Data Sourced
via MITRE·02:47 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9431?
CVE-2017-9431 is classified as a high-severity vulnerability due to the potential for an out-of-bounds write leading to a heap-based buffer overflow.
2
How do I fix CVE-2017-9431?
To fix CVE-2017-9431, upgrade gRPC to version 1.2.3 or later, as this version addresses the vulnerability.
3
What impact does CVE-2017-9431 have on gRPC applications?
CVE-2017-9431 can lead to crashes or arbitrary code execution in gRPC applications if exploited.
4
Is CVE-2017-9431 present in all versions of gRPC?
CVE-2017-9431 affects all versions of gRPC before 1.2.3.
5
What components are affected by CVE-2017-9431?
CVE-2017-9431 specifically affects the core library components related to error handling in gRPC.