CVE-2023-28793

Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:linux:*:*

History

21 Nov 2024, 07:56

Type Values Removed Values Added
References () https://help.zscaler.com/client-connector/client-connector-app-release-summary-2022?applicable_category=Linux&applicable_version=1.3.1&deployment_date=2022-09-19 - Release Notes () https://help.zscaler.com/client-connector/client-connector-app-release-summary-2022?applicable_category=Linux&applicable_version=1.3.1&deployment_date=2022-09-19 - Release Notes

17 Oct 2024, 15:15

Type Values Removed Values Added
Summary (en) Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. (en) Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
CWE CWE-94

27 Oct 2023, 00:41

Type Values Removed Values Added
First Time Zscaler client Connector
Zscaler
CWE CWE-787
CPE cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:linux:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References (MISC) https://help.zscaler.com/client-connector/client-connector-app-release-summary-2022?applicable_category=Linux&applicable_version=1.3.1&deployment_date=2022-09-19 - (MISC) https://help.zscaler.com/client-connector/client-connector-app-release-summary-2022?applicable_category=Linux&applicable_version=1.3.1&deployment_date=2022-09-19 - Release Notes

23 Oct 2023, 14:27

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-23 14:15

Updated : 2024-11-21 07:56


NVD link : CVE-2023-28793

Mitre link : CVE-2023-28793

CVE.ORG link : CVE-2023-28793


JSON object : View

Products Affected

zscaler

  • client_connector
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-787

Out-of-bounds Write