Page MenuHomeFreeBSD

security/vuxml: Add sysutils/eza vulnerability
ClosedPublic

Authored by dutra on Feb 13 2024, 6:46 PM.
Tags
None
Referenced Files
F147295467: D43868.id134341.diff
Mon, Mar 9, 6:32 PM
Unknown Object (File)
Sat, Mar 7, 8:02 PM
Unknown Object (File)
Mon, Feb 23, 11:42 PM
Unknown Object (File)
Sat, Feb 21, 11:38 PM
Unknown Object (File)
Feb 8 2026, 9:19 AM
Unknown Object (File)
Feb 8 2026, 5:22 AM
Unknown Object (File)
Feb 8 2026, 1:23 AM
Unknown Object (File)
Jan 31 2026, 2:02 PM
Subscribers
None

Details

Summary
This release fixes the vulnerability:
https://github.com/eza-community/eza/releases/tag/v0.18.2

Approved by:	dbaio (mentor), garga (mentor)

Pkg audit test:

eza is vulnerable:
  Affected versions:
  < 0.18.2
  Libgit2 -- multiple vulnerabilities
  CVE: CVE-2024-24577
  WWW: https://vuxml.FreeBSD.org/freebsd/43768ff3-c683-11ee-97d0-001b217b3468.html

1 problem(s) in 1 installed package(s) found.

Diff Detail

Repository
R11 FreeBSD ports repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

dutra requested review of this revision.Feb 13 2024, 6:46 PM
dutra created this revision.
This revision is now accepted and ready to land.Feb 14 2024, 12:25 PM
dbaio requested changes to this revision.Feb 14 2024, 12:33 PM

And add some information into the commit message, like, 'Include eza port in the Libgit2 entry, as it is a Go port that uses it as a dependency'.

security/vuxml/vuln/2024.xml
441–445

Add a modified entry here.

<modified>2024-02-14</modified>
This revision now requires changes to proceed.Feb 14 2024, 12:33 PM

security/vuxml: Add sysutils/eza vulnerability

Include eza port in the Libgit2 entry

Approved by: dbaio (mentor), garga (mentor)

This revision is now accepted and ready to land.Feb 14 2024, 7:43 PM