CVE-2021-42389: Divide by Zero
Published Mar 14, 2022
·Updated
Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.
Affected Software
2 affected components
Yandex Clickhouse<21.10.2.15
Clickhouse Clickhouse<21.10.2.15
Event History
Mar 14, 2022
CVE Published
via MITRE·10:20 PM
Data Sourced
via MITRE·10:20 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-42389?
CVE-2021-42389 is classified as a high severity vulnerability due to the potential for remote code execution and denial of service.
2
How do I fix CVE-2021-42389?
To mitigate CVE-2021-42389, upgrade Clickhouse to version 21.10.2.15 or later.
3
What causes the CVE-2021-42389 vulnerability?
CVE-2021-42389 is caused by a divide-by-zero issue in Clickhouse's Delta compression codec when processing a malicious query.
4
Which versions of Clickhouse are affected by CVE-2021-42389?
CVE-2021-42389 affects versions of Clickhouse prior to 21.10.2.15.
5
What actions should I take if I am using an affected version of Clickhouse?
If using an affected version of Clickhouse, it is essential to update to the patched version immediately to avoid exploitation.