Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qx3-6hxr-j2ch

Опубликовано: 08 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 8.4

Описание

eza Potential Heap Overflow Vulnerability for AArch64

Summary

In eza, there exists a potential heap overflow vulnerability, first seen when using Ubuntu for Raspberry Pi series system, on ubuntu-raspi kernel, relating to the .git directory.

Details

The vulnerability seems to be triggered by the .git directory in some projects. This issue may be related to specific files, and the directory structure also plays a role in triggering the vulnerability. Files/folders that may be involved in triggering the vulnerability include .git/HEAD, .git/refs, and .git/objects.

As @polly pointed out to me, this is likely caused by GHSA-j2v7-4f6v-gpg8, which we do seem to use currently.

PoC

For more information check @CuB3y0nd's blogpost blog.

Impact

Arbitrary code execution.

Пакеты

Наименование

eza

rust
Затронутые версииВерсия исправления

< 0.18.2

0.18.2

EPSS

Процентиль: 21%
0.00067
Низкий

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 2 года назад

Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components.

CVSS3: 7.8
nvd
почти 2 года назад

Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components.

CVSS3: 7.8
debian
почти 2 года назад

Buffer Overflow vulnerability in eza before version 0.18.2, allows loc ...

EPSS

Процентиль: 21%
0.00067
Низкий

8.4 High

CVSS3