CVE-2019-16535

In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.
References
Configurations

Configuration 1

cpe:2.3:a:yandex:clickhouse:*:*:*:*:*:*:*:*

Information

Published : 2019-12-30 03:15

Updated : 2020-01-03 04:40


NVD link : CVE-2019-16535

Mitre link : CVE-2019-16535

Products Affected
No products.
CWE
CWE-125

Out-of-bounds Read

CWE-191

Integer Underflow (Wrap or Wraparound)

CWE-787