High severity7.8NVD Advisory· Published Mar 6, 2024· Updated Jun 17, 2026
CVE-2024-25817
CVE-2024-25817
Description
Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ezacrates.io | < 0.18.2 | 0.18.2 |
Affected products
3- eza/ezadescription
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-3qx3-6hxr-j2chnvdPatchThird Party AdvisoryADVISORY
- github.com/eza-community/eza/commit/47c9b90368c49117ba42760bd58acafa3362cbd4ghsaWEB
- github.com/eza-community/eza/security/advisories/GHSA-3qx3-6hxr-j2chghsaWEB
- www.cubeyond.net/blog/my-cves/eza-cve-reportnvdBroken Link
News mentions
0No linked articles in our index yet.