Lucene search

K
cvelistJFROGCVELIST:CVE-2021-42391
HistoryMar 14, 2022 - 10:20 p.m.

CVE-2021-42391

2022-03-1422:20:33
CWE-369
JFROG
www.cve.org
4
clickhouse
gorilla compression
divide-by-zero
malicious query
modulo operation
buffer.

EPSS

0.001

Percentile

34.1%

Divide-by-zero in Clickhouse’s Gorilla compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.

CNA Affected

[
  {
    "product": "clickhouse",
    "vendor": "yandex",
    "versions": [
      {
        "lessThan": "21.10.2.15-stable",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

EPSS

0.001

Percentile

34.1%

Related for CVELIST:CVE-2021-42391