Heap-based buffer overflow in grpc - CVE-2017-7860
Published: July 21, 2022
grpc
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to a heap-based buffer overflow in parse_unix function in core/ext/client_channel/parse_address.c. A remote attacker can send a specially crafted file the affected software, trigger heap-based buffer overflow and execute arbitrary code on the target system.