Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-42389

Опубликовано: 14 мар. 2022
Источник: debian
EPSS Низкий

Описание

Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
clickhousenot-affectedpackage

Примечания

  • https://jfrog.com/blog/7-rce-and-dos-vulnerabilities-found-in-clickhouse-dbms/

EPSS

Процентиль: 67%
0.00533
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.

CVSS3: 6.5
github
почти 4 года назад

Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.

EPSS

Процентиль: 67%
0.00533
Низкий