PT-2021-23612 · Unknown+2 · Clickhouse+1

Or Peles

+1

·

Published

2021-10-18

·

Updated

2025-06-25

·

CVE-2021-42390

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Clickhouse (affected versions not specified)
Description The issue is related to a divide-by-zero error in Clickhouse's DeltaDouble compression codec. This occurs when parsing a malicious query, where the first byte of the compressed buffer is used in a modulo operation without being checked for 0.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Divide By Zero

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1418
ALT-PU-2022-1601
ALT-PU-2022-1682
CVE-2021-42390

Affected Products

Alt Linux
Clickhouse