In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://clickhouse.yandex/docs/en/security_changelog/ |
![]() ![]() |
History
Wed, 25 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Clickhouse
Clickhouse clickhouse |
|
CPEs | cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:* | |
Vendors & Products |
Yandex
Yandex clickhouse |
Clickhouse
Clickhouse clickhouse |

Status: PUBLISHED
Assigner: yandex
Published: 2019-12-30T14:35:21
Updated: 2024-08-05T01:17:40.278Z
Reserved: 2019-09-19T00:00:00
Link: CVE-2019-16535

No data.

Status : Modified
Published: 2019-12-30T15:15:10.673
Modified: 2025-06-25T20:48:54.637
Link: CVE-2019-16535

No data.