Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-42387

Опубликовано: 14 мар. 2022
Источник: nvd
CVSS3: 8.1
CVSS2: 5.5
EPSS Низкий

Описание

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the upper bounds of the source of the copy operation.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:*
Версия до 21.10.2.15 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 54%
0.00316
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-125
CWE-125

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 4 года назад

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the upper bounds of the source of the copy operation.

CVSS3: 8.1
debian
почти 4 года назад

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when par ...

CVSS3: 8.1
github
почти 4 года назад

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the upper bounds of the source of the copy operation.

EPSS

Процентиль: 54%
0.00316
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-125
CWE-125