PT-2021-11268 · Unknown+1 · Clickhouse-Driver+1

Xzkostyan

·

Published

2021-01-06

·

Updated

2024-03-06

·

CVE-2020-26759

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: clickhouse-driver versions prior to 0.1.5
Description: The issue allows a malicious clickhouse server to trigger a crash or execute arbitrary code on a database client via a crafted server response, due to a buffer overflow.
Recommendations: For versions prior to 0.1.5, update to version 0.1.5 or later to resolve the issue. As a temporary workaround, consider restricting access to untrusted clickhouse servers to minimize the risk of exploitation.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1390
ALT-PU-2021-1608
ALT-PU-2022-2172
BIT-CLICKHOUSE-2020-26759
CVE-2020-26759
GHSA-VGV5-CXVH-VFXH
PYSEC-2021-61

Affected Products

Alt Linux
Clickhouse-Driver