CVE-2024-41436: Buffer Overflow
Published Sep 3, 2024
·Updated
ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.
Affected Software
2 affected components
Clickhouse Clickhouse
Clickhouse Clickhouse=24.3.3.102
Event History
Sep 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-41436?
CVE-2024-41436 is classified as a buffer overflow vulnerability, which can lead to potential code execution.
2
How do I fix CVE-2024-41436?
To remediate CVE-2024-41436, you should update ClickHouse to a patched version that addresses this vulnerability.
3
Which versions of ClickHouse are affected by CVE-2024-41436?
CVE-2024-41436 affects ClickHouse version 24.3.3.102.
4
What components are involved in CVE-2024-41436?
CVE-2024-41436 is related to the DB::evaluateConstantExpressionImpl component in ClickHouse.
5
Is CVE-2024-41436 exploitable remotely?
Yes, CVE-2024-41436 can be exploited remotely if the vulnerable component is exposed.