Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-42388

Опубликовано: 14 мар. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.5
CVSS3: 8.1

Описание

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the lower bounds of the source of the copy operation.

РелизСтатусПримечание
devel

DNE

esm-apps/focal

released

18.16.1+ds-7ubuntu0.1
esm-apps/noble

not-affected

18.16.1+ds-7.4build2
focal

released

18.16.1+ds-7ubuntu0.1
impish

ignored

end of life
lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage
noble

not-affected

18.16.1+ds-7.4build2
upstream

released

18.16.1+ds-7.4

Показывать по

EPSS

Процентиль: 58%
0.00365
Низкий

5.5 Medium

CVSS2

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
почти 4 года назад

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the lower bounds of the source of the copy operation.

CVSS3: 8.1
debian
почти 4 года назад

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when par ...

CVSS3: 8.1
github
почти 4 года назад

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the lower bounds of the source of the copy operation.

EPSS

Процентиль: 58%
0.00365
Низкий

5.5 Medium

CVSS2

8.1 High

CVSS3