{"id":"CVE-2017-7860","details":"Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/ext/client_channel/parse_address.c.","modified":"2026-08-07T14:53:40.595559Z","published":"2017-04-14T04:59:00.383Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/97695"},{"type":"ADVISORY","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=661"},{"type":"FIX","url":"https://github.com/grpc/grpc/pull/9833"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grpc/grpc","events":[{"introduced":"0"},{"last_affected":"fa301e3674a1cc786eb4dd4253a0e677f2eb68e3"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.1.2"}],"source":"CPE_RANGE"}}],"versions":["v1.1.1","v1.1.2","v1.1.0","v1.1.0-pre1","release-0_9_1-objectivec-0.5.1","release-0_9_0","release-0_6_0","release-0_6","release_test"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7860.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/grpc/grpc-java","events":[{"introduced":"0"},{"last_affected":"8c79bc9006dbafcb6c910287b1c89bd9281c8880"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.1.2"}],"source":"CPE_RANGE"}}],"versions":["v1.1.2","v1.1.1","v1.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7860.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/grpc/grpc-node","events":[{"introduced":"0"},{"last_affected":"62bee3876e92a94da4ee86b18763c5bd00704630"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.1.2"}],"source":"CPE_RANGE"}}],"versions":["@grpc/grpc-js@1.1.2","@grpc/grpc-js@1.1.0","grpc@1.24.3","@grpc/grpc-js@1.0.5","@grpc/grpc-js@1.0.2","grpc-tools@1.9.0","@grpc/grpc-js@1.0.4","@grpc/grpc-js@1.0.3","@grpc/grpc-js@1.0.0","@grpc/grpc-js@0.7.9","@grpc/grpc-js@0.8.1","@grpc/grpc-js@0.8.0","@grpc/grpc-js@0.7.6","@grpc/grpc-js@0.7.5","@grpc/proto-loader@0.5.4","@grpc/grpc-js@0.7.2","@grpc/grpc-js@0.7.1","@grpc/grpc-js@0.7.0","@grpc/grpc-js@0.6.18","@grpc/grpc-js@0.6.12","@grpc/grpc-js@0.6.5","grpc@1.23.4","@grpc/grpc-js@0.6.4","@grpc/grpc-js@0.6.3","@grpc/grpc-js@0.6.2","@grpc/grpc-js@0.6.1","@grpc/grpc-js@0.6.0","@grpc/grpc-js@0.5.3","@grpc/proto-loader@0.5.2","@grpc/grpc-js@0.5.0","@grpc/grpc-js@0.5.2","@grpc/grpc-js@0.5.1","grpc-tools@1.8.0","@grpc/grpc-js@0.4.3","@grpc/grpc-js@0.4.2","@grpc/proto-loader@0.5.1","@grpc/grpc-js@0.4.0","@grpc/proto-loader@0.5.0","grpc-tools@1.7.2","@grpc/grpc-js@0.3.6","grpc-tools@1.7.0","@grpc/proto-loader@0.4.0","@grpc/grpc-js@0.3.4","@grpc/grpc-js@0.3.3","@grpc/grpc-js@0.3.1","@grpc/grpc-js@0.3.0","@grpc/proto-loader@0.3.0","@grpc/grpc-js@0.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7860.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}