In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://clickhouse.yandex/docs/en/security_changelog/ |
History
No history.
MITRE
Status: PUBLISHED
Assigner: yandex
Published: 2019-12-30T14:35:21
Updated: 2024-08-05T01:17:40.278Z
Reserved: 2019-09-19T00:00:00
Link: CVE-2019-16535
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-12-30T15:15:10.673
Modified: 2024-11-21T04:30:47.033
Link: CVE-2019-16535
Redhat
No data.