CVE-2019-16535

In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yandex:clickhouse:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:30

Type Values Removed Values Added
References () https://clickhouse.yandex/docs/en/security_changelog/ - Vendor Advisory () https://clickhouse.yandex/docs/en/security_changelog/ - Vendor Advisory

Information

Published : 2019-12-30 15:15

Updated : 2024-11-21 04:30


NVD link : CVE-2019-16535

Mitre link : CVE-2019-16535

CVE.ORG link : CVE-2019-16535


JSON object : View

Products Affected

yandex

  • clickhouse
CWE
CWE-125

Out-of-bounds Read

CWE-191

Integer Underflow (Wrap or Wraparound)

CWE-787

Out-of-bounds Write