PT-2021-6323 · Unknown+2 · Clickhouse+1

Or Peles

+1

·

Published

2021-10-18

·

Updated

2022-12-08

·

CVE-2021-43304

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ClickHouse (affected versions not specified)
Description The issue is related to a heap buffer overflow in ClickHouse's LZ4 compression codec. This occurs when parsing a malicious query, as there is no verification that copy operations do not exceed the destination buffer's limits. Specifically, the arbitrary copy operation in the LZ4::decompressImpl loop can lead to this overflow. An attacker could potentially exploit this vulnerability to execute arbitrary code remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1418
ALT-PU-2022-1601
ALT-PU-2022-1682
BDU:2022-01316
CVE-2021-43304
DLA-3176-1

Affected Products

Alt Linux
Clickhouse