Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4xq2-q58f-2q5m

Опубликовано: 23 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could cause a heap buffer overflow and crash the server by inserting a malformed CapnProto object. The fixed versions are 22.9.1.2603, 22.8.2.11, 22.7.4.16, 22.6.6.16, and 22.3.12.19.

An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could cause a heap buffer overflow and crash the server by inserting a malformed CapnProto object. The fixed versions are 22.9.1.2603, 22.8.2.11, 22.7.4.16, 22.6.6.16, and 22.3.12.19.

EPSS

Процентиль: 30%
0.00113
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 лет назад

An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could cause a heap buffer overflow and crash the server by inserting a malformed CapnProto object. The fixed versions are 22.9.1.2603, 22.8.2.11, 22.7.4.16, 22.6.6.16, and 22.3.12.19.

CVSS3: 6.5
nvd
около 2 лет назад

An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could cause a heap buffer overflow and crash the server by inserting a malformed CapnProto object. The fixed versions are 22.9.1.2603, 22.8.2.11, 22.7.4.16, 22.6.6.16, and 22.3.12.19.

CVSS3: 6.5
debian
около 2 лет назад

An issue was discovered in ClickHouse before 22.9.1.2603. An authentic ...

EPSS

Процентиль: 30%
0.00113
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-787