CVE-2023-48704: Unauthenticated heap buffer overflow in Gorrila codec decompression
ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface exposed by default on port 9000/tcp, triggering a bug in the decompression logic of Gorilla codec that crashes the ClickHouse server process. This attack does not require authentication. This issue has been addressed in ClickHouse Cloud version 23.9.2.47551 and ClickHouse versions 23.10.5.20, 23.3.18.15, 23.8.8.20, and 23.9.6.20.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48704?
CVE-2023-48704 is classified as a high-severity vulnerability due to the potential for a heap buffer overflow exploitation in ClickHouse.
How do I fix CVE-2023-48704?
To fix CVE-2023-48704, you should update to a patched version of ClickHouse that addresses the heap buffer overflow issue.
What versions of ClickHouse are affected by CVE-2023-48704?
CVE-2023-48704 affects ClickHouse versions from 23.3.0 to 23.10.5 and ClickHouse Cloud versions prior to 23.9.2.47551.
What type of vulnerability is CVE-2023-48704?
CVE-2023-48704 is a heap buffer overflow vulnerability that can be exploited through specially crafted payloads.
Can CVE-2023-48704 be exploited remotely?
Yes, CVE-2023-48704 can potentially be exploited remotely through attacks targeting the native interface of the ClickHouse server.