Unknown · Clickhouse-Driver · CVE-2020-26759
Name of the Vulnerable Software and Affected Versions:
clickhouse-driver versions prior to 0.1.5
Description:
The issue allows a malicious clickhouse server to trigger a crash or execute arbitrary code on a database client via a crafted server response, due to a buffer overflow.
Recommendations:
For versions prior to 0.1.5, update to version 0.1.5 or later to resolve the issue. As a temporary workaround, consider restricting access to untrusted clickhouse servers to minimize the risk of exploitation.