CVE-2018-14671: Input Validation
Published Aug 15, 2019
·Updated
In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability.
Affected Software
2 affected components
Yandex Clickhouse<18.10.3
Clickhouse Clickhouse<18.10.3
Event History
Aug 15, 2019
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-14671?
CVE-2018-14671 is considered critical due to its potential for Remote Code Execution.
2
How do I fix CVE-2018-14671?
To fix CVE-2018-14671, upgrade ClickHouse to version 18.10.3 or later.
3
What causes CVE-2018-14671?
CVE-2018-14671 is caused by unixODBC allowing the loading of arbitrary shared objects from the file system.
4
Can CVE-2018-14671 be exploited remotely?
Yes, CVE-2018-14671 can be exploited remotely, which poses a significant security risk.
5
Which versions of ClickHouse are affected by CVE-2018-14671?
All versions of ClickHouse before 18.10.3 are affected by CVE-2018-14671.