Home

Description

Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3.

PUBLISHED Reserved 2019-09-19 | Published 2025-05-21 | Updated 2025-05-21 | Assigner yandex




HIGH: 8.2CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

Problem types

CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Product status

Default status
unaffected

19.14.3.3 (semver)
affected

Credits

Eldar Zaitov of Yandex Information Security Team finder

References

clickhouse.com/docs/whats-new/security-changelog

cve.org (CVE-2019-16536)

nvd.nist.gov (CVE-2019-16536)

Download JSON