CVE-2019-16535

I

n all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.

Configurations

Configuration 1 (hide)

cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:*

History

25 Jun 2025, 20:48

Type Values Removed Values Added
CPE cpe:2.3:a:yandex:clickhouse:*:*:*:*:*:*:*:* cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:*
First Time Clickhouse
Clickhouse clickhouse

21 Nov 2024, 04:30

Type Values Removed Values Added
References () https://clickhouse.yandex/docs/en/security_changelog/ - Vendor Advisory () https://clickhouse.yandex/docs/en/security_changelog/ - Vendor Advisory

Information

Published : 2019-12-30 15:15

Updated : 2025-06-25 20:48


NVD link : CVE-2019-16535

Mitre link : CVE-2019-16535

CVE.ORG link : CVE-2019-16535


JSON object : View

Products Affected
CWE
CWE-125

Out-of-bounds Read

CWE-191

Integer Underflow (Wrap or Wraparound)

CWE-787

Out-of-bounds Write