CVE-2023-28798: Out-of-bounds write to heap in pacparser
Published May 2, 2024
·Updated
An out-of-bounds write to heap in the pacparser library on Zscaler Client Connector on Mac may lead to arbitrary code execution.
Affected Software
3 affected components
Zscaler Client Connector
pacparser pacparser
Zscaler Client Connector Macos<3.7
Event History
May 2, 2024
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:23 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-28798?
CVE-2023-28798 is classified as a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2023-28798?
To fix CVE-2023-28798, upgrade to the latest version of Zscaler Client Connector that addresses the vulnerability.
3
What are the implications of CVE-2023-28798?
The implications of CVE-2023-28798 include potential unauthorized access and execution of malicious code on affected systems.
4
Which software is affected by CVE-2023-28798?
CVE-2023-28798 specifically affects the pacparser library within the Zscaler Client Connector on macOS.
5
Can CVE-2023-28798 affect non-Mac systems?
No, CVE-2023-28798 specifically targets the macOS version of the Zscaler Client Connector and does not impact other operating systems.