CVE-2019-16535

In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.
Configurations

Configuration 1 (hide)

cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:*

History

25 Jun 2025, 20:48

Type Values Removed Values Added
CPE cpe:2.3:a:yandex:clickhouse:*:*:*:*:*:*:*:* cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:*
References (MISC) https://clickhouse.yandex/docs/en/security_changelog/ - Vendor Advisory () https://clickhouse.yandex/docs/en/security_changelog/ - Vendor Advisory
First Time Clickhouse clickhouse
Clickhouse

Information

Published : 2019-12-30 15:15

Updated : 2025-06-25 20:48


NVD link : CVE-2019-16535

Mitre link : CVE-2019-16535


JSON object : View

Products Affected

clickhouse

  • clickhouse
CWE
CWE-787

Out-of-bounds Write

CWE-191

Integer Underflow (Wrap or Wraparound)

CWE-125

Out-of-bounds Read