CVE-2023-28793: Heap Based Buffer Overflow in Library
Published Oct 23, 2023
·Updated
Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
Affected Software
1 affected component
Zscaler Client Connector Linux<1.3.1.6
Event History
Oct 23, 2023
CVE Published
01:26 PM
Data Sourced
01:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-28793?
CVE-2023-28793 is a buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux, allowing code injection.
2
Which version of Zscaler Client Connector for Linux is affected by CVE-2023-28793?
Zscaler Client Connector for Linux version before 1.3.1.6 is affected by CVE-2023-28793.
3
What is the severity of CVE-2023-28793?
The severity of CVE-2023-28793 is high, with a CVSS score of 7.8.
4
How can I fix CVE-2023-28793?
To fix CVE-2023-28793, update Zscaler Client Connector for Linux to version 1.3.1.6 or later.
5
Where can I find more information about CVE-2023-28793?
You can find more information about CVE-2023-28793 in the Zscaler Client Connector App Release Summary for Linux.