CVE-2024-25817

NameCVE-2024-25817
DescriptionBuffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rust-eza (PTS)trixie0.20.8-1fixed
sid0.20.9-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rust-ezasource(unstable)0.18.2-1

Notes

https://github.com/advisories/GHSA-3qx3-6hxr-j2ch

Search for package or bug name: Reporting problems