VDB
Sign up
HIGH8.4

GHSA-3qx3-6hxr-j2ch

eza Potential Heap Overflow Vulnerability for AArch64

Details

### Summary In `eza`, there exists a potential heap overflow vulnerability, first seen when using Ubuntu for Raspberry Pi series system, on `ubuntu-raspi` kernel, relating to the `.git` directory.

### Details The vulnerability seems to be triggered by the `.git` directory in some projects. This issue may be related to specific files, and the directory structure also plays a role in triggering the vulnerability. Files/folders that may be involved in triggering the vulnerability include `.git/HEAD`, `.git/refs`, and `.git/objects`.

As @polly pointed out to me, this is likely caused by [GHSA-j2v7-4f6v-gpg8](https://github.com/libgit2/libgit2/security/advisories/GHSA-j2v7-4f6v-gpg8), which we do seem to use currently.

### PoC For more information check @CuB3y0nd's blogpost [blog](https://www.cubeyond.net/blog/eza-cve-report).

### Impact Arbitrary code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/eza
Introduced in: 0Fixed in: 0.18.2

Upgrade eza to 0.18.2 or newer (ecosystem crates.io).

References