CVE-2023-48298
ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. This vulnerability is an integer underflow resulting in crash due to stack buffer overflow in decompression of FPC codec. It can be triggered and exploited by an unauthenticated attacker. The vulnerability is very similar to CVE-2023-47118 with how the vulnerable function can be exploited.
Published:Dec 21, 2023
Last Modified:Nov 27, 2024
EPS:Dec 21, 2023
EPSS Score:0.00467
CVSS Score:5.9
Affected Products
Vendor
Product
Action
Vendor
Clickhouse
Product
Clickhouse
Clickhouse
Clickhouse
Vendor
Clickhouse
Product
Clickhouse Cloud
Clickhouse
Clickhouse Cloud
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
