ZeroHour

CVE-2019-16535

CVSS 3.1
9.8 critical
EPSS
2%p76
Published
()
Modified
Description

In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.

Vendors
clickhouse
Products
clickhouse
Weakness
CWE-125, CWE-191, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.