← Back to CVEs
CVE-2023-48298
MEDIUM5.9
Description
ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. This vulnerability is an integer underflow resulting in crash due to stack buffer overflow in decompression of FPC codec. It can be triggered and exploited by an unauthenticated attacker. The vulnerability is very similar to CVE-2023-47118 with how the vulnerable function can be exploited.
CVE Details
CVSS v3.1 Score5.9
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
Published12/21/2023
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
clickhouse:clickhouseclickhouse:clickhouse_cloud
Weaknesses (CWE)
CWE-191
References
https://github.com/ClickHouse/ClickHouse/pull/56795(security-advisories@github.com)
https://github.com/ClickHouse/ClickHouse/security/advisories/GHSA-qw9f-qv29-8938(security-advisories@github.com)
https://github.com/ClickHouse/ClickHouse/pull/56795(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/ClickHouse/ClickHouse/security/advisories/GHSA-qw9f-qv29-8938(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.