Fedora Account System
Red Hat Associate
Red Hat Customer
Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components. https://github.com/advisories/GHSA-3qx3-6hxr-j2ch https://www.cubeyond.net/blog/my-cves/eza-cve-report
Created rust-eza tracking bugs for this issue: Affects: fedora-all [bug 2268035]
Note: It appears that this is actually a vulnerability from libgit2 that has already been handled separately: https://github.com/libgit2/libgit2/security/advisories/GHSA-j2v7-4f6v-gpg8