PT-2023-30912 · Unknown+1 · Gorilla Codec+2

Malacupa

·

Publicado

2023-11-26

·

Atualizado

2024-01-02

·

CVE-2023-48704

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ClickHouse versions 23.3.18.15, 23.8.8.20, 23.9.6.20, 23.10.5.20 ClickHouse Cloud version 23.9.2.47551
Description A heap buffer overflow issue was discovered in the ClickHouse server, allowing an attacker to send a specially crafted payload to the native interface exposed by default on port 9000/tcp. This triggers a bug in the decompression logic of the Gorilla codec, causing the ClickHouse server process to crash. The attack does not require authentication.
Recommendations For ClickHouse version 23.3.18.15, update to version 23.3.18.15 or later. For ClickHouse version 23.8.8.20, update to version 23.8.8.20 or later. For ClickHouse version 23.9.6.20, update to version 23.9.6.20 or later. For ClickHouse version 23.10.5.20, update to version 23.10.5.20 or later. For ClickHouse Cloud version 23.9.2.47551, no additional action is required as this version already includes the fix. As a temporary workaround, consider restricting access to the native interface on port 9000/tcp to minimize the risk of exploitation.

Exploit

Correção

Heap Based Buffer Overflow

Buffer Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-48704
GHSA-5RMF-5G48-XV63

Produtos afetados

Clickhouse
Clickhouse Cloud
Gorilla Codec