PT-2021-6324 · Unknown+4 · Clickhouse+3

Or Peles

+1

·

Published

2021-10-18

·

Updated

2024-07-31

·

CVE-2021-43305

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ClickHouse (affected versions not specified)
Description The issue is related to a heap buffer overflow in ClickHouse's LZ4 compression codec. This occurs when parsing a malicious query, as there is no verification that copy operations in the LZ4::decompressImpl loop do not exceed the destination buffer's limits. The vulnerable copy operation is in a different wildCopy call, making it similar to a previously identified issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1418
ALT-PU-2022-1601
ALT-PU-2022-1682
BDU:2022-01317
CVE-2021-43305
DLA-3176-1
USN-6933-1

Affected Products

Alt Linux
Clickhouse
Linuxmint
Ubuntu