CVE-2023-28793

Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:linux:*:*

History

17 Oct 2024, 15:15

Type Values Removed Values Added
Summary (en) Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. (en) Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
CWE CWE-94

27 Oct 2023, 00:41

Type Values Removed Values Added
CWE CWE-787
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Zscaler client Connector
Zscaler
References (MISC) https://help.zscaler.com/client-connector/client-connector-app-release-summary-2022?applicable_category=Linux&applicable_version=1.3.1&deployment_date=2022-09-19 - (MISC) https://help.zscaler.com/client-connector/client-connector-app-release-summary-2022?applicable_category=Linux&applicable_version=1.3.1&deployment_date=2022-09-19 - Release Notes
CPE cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:linux:*:*

23 Oct 2023, 14:27

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-23 14:15

Updated : 2024-10-17 15:15


NVD link : CVE-2023-28793

Mitre link : CVE-2023-28793

CVE.ORG link : CVE-2023-28793


JSON object : View

Products Affected

zscaler

  • client_connector
CWE
CWE-787

Out-of-bounds Write

CWE-94

Improper Control of Generation of Code ('Code Injection')