Home
HIGH: 8.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:HDefault status
unaffected
19.14.3.3 (semver)
affected
Description
Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3.
Problem types
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
19.14.3.3 (semver)
Credits
Eldar Zaitov of Yandex Information Security Team
References
clickhouse.com/docs/whats-new/security-changelog