Описание
Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 21.10.2.15 (исключая)
cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00533
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-369
CWE-369
Связанные уязвимости
CVSS3: 6.5
debian
почти 4 года назад
Divide-by-zero in Clickhouse's Delta compression codec when parsing a ...
CVSS3: 6.5
github
почти 4 года назад
Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.
EPSS
Процентиль: 67%
0.00533
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-369
CWE-369