Credits: Eldar Zaitov of Yandex Information Security Team
CVE-2019-16535
Аn OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.
Credits: Eldar Zaitov of Yandex Information Security Team
CVE-2019-16536
Stack overflow leading to DoS can be triggered by a malicious authenticated client.
Credits: Eldar Zaitov of Yandex Information Security Team
Fixed in ClickHouse Release 19.13.6.1, 2019-09-20
Credits: Nikita Tikhomirov
CVE-2018-14672
Functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.
Credits: Andrey Krasichkov of Yandex Information Security Team
Fixed in ClickHouse Release 18.10.3, 2018-08-13
CVE-2018-14671
unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability.
Credits: Andrey Krasichkov and Evgeny Sidorov of Yandex Information Security Team
Credits: Andrey Krasichkov of Yandex Information Security Team
Fixed in ClickHouse Release 1.1.54390, 2018-07-06
CVE-2018-14669
ClickHouse MySQL client had “LOAD DATA LOCAL INFILE” functionality enabled that allowed a malicious MySQL database read arbitrary files from the connected ClickHouse server.
Credits: Andrey Krasichkov and Evgeny Sidorov of Yandex Information Security Team
CVE-2018-14670
Incorrect configuration in deb package could lead to the unauthorized use of the database.
Credits: the UK’s National Cyber Security Centre (NCSC)