PYSEC-2017-101

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/grpcio/PYSEC-2017-101.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2017-101
Aliases
Published
2017-04-30T17:59:00Z
Modified
2023-11-01T04:48:22.908553Z
Summary
[none]
Details

Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpccalldestroy function in core/lib/surface/call.c.

References

Affected packages

PyPI / grpcio

Package

Affected ranges

Type
GIT
Repo
https://github.com/grpc/grpc
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.0

Affected versions

0.*

0.3.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0a3
0.4.0a4
0.4.0a5
0.4.0a6
0.4.0a7
0.4.0a8
0.4.0a13
0.4.0a14
0.4.0
0.5.0a0
0.5.0a1
0.5.0a2
0.9.0a0
0.9.0a1
0.10.0a0
0.11.0b0
0.11.0b1
0.12.0b0
0.12.0b8
0.13.0
0.13.1rc1
0.13.1
0.14.0rc1
0.14.0
0.15.0

1.*

1.0.0rc1
1.0.0rc2
1.0.0
1.0.1rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.3
1.2.0
1.2.1