PT-2023-30912 · Unknown+1 · Gorilla Codec+2

Malacupa

·

Published

2023-11-26

·

Updated

2024-01-02

·

CVE-2023-48704

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ClickHouse versions 23.3.18.15, 23.8.8.20, 23.9.6.20, 23.10.5.20 ClickHouse Cloud version 23.9.2.47551
Description A heap buffer overflow issue was discovered in the ClickHouse server, allowing an attacker to send a specially crafted payload to the native interface exposed by default on port 9000/tcp. This triggers a bug in the decompression logic of the Gorilla codec, causing the ClickHouse server process to crash. The attack does not require authentication.
Recommendations For ClickHouse version 23.3.18.15, update to version 23.3.18.15 or later. For ClickHouse version 23.8.8.20, update to version 23.8.8.20 or later. For ClickHouse version 23.9.6.20, update to version 23.9.6.20 or later. For ClickHouse version 23.10.5.20, update to version 23.10.5.20 or later. For ClickHouse Cloud version 23.9.2.47551, no additional action is required as this version already includes the fix. As a temporary workaround, consider restricting access to the native interface on port 9000/tcp to minimize the risk of exploitation.

Exploit

Fix

Heap Based Buffer Overflow

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2023-48704
GHSA-5RMF-5G48-XV63

Affected Products

Clickhouse
Clickhouse Cloud
Gorilla Codec