Re: Buffer overflow in zic

2025-03-28 Thread Tom Lane
=?UTF-8?B?0JXQstCz0LXQvdC40Lkg0JPQvtGA0LHQsNC90LXQsg==?= writes: > Bug fixed in 2025b: > https://lists.iana.org/hyperkitty/list/tz-annou...@iana.org/thread/6JVHNHLB6I2WAYTQ75L6KEPEQHFXAJK3/ We'll get around to syncing to tzcode 2025b or later at some point. This particular issue does not strike

Re: Buffer overflow in zic

2025-03-28 Thread Евгений Горбанев
Bug fixed in 2025b: https://lists.iana.org/hyperkitty/list/tz-annou...@iana.org/thread/6JVHNHLB6I2WAYTQ75L6KEPEQHFXAJK3/ Mailing list: https://lists.iana.org/hyperkitty/list/t...@iana.org/thread/7MKA4UXVUUGXXMDCTPQ5VOLD4KKN3LQR/ 06.02.2025 21:00, Tom Lane пишет: Evgeniy Gorbanyov writes: Ifyo

Re: Buffer overflow in zic

2025-02-06 Thread Tom Lane
Evgeniy Gorbanyov writes: > Ifyou compilezicwithASAN,you cangetthe following(notethiswill > delete/etc/localtime): > |$ sudo ./zic -l fff zic is not our code. Please take this up with the upstream IANA list t...@iana.org. (They might want to see a reproducer against their current code ... we'r

Buffer overflow in zic

2025-02-05 Thread Evgeniy Gorbanyov
Hello. Ifyou compilezicwithASAN,you cangetthe following(notethiswill delete/etc/localtime): |$ sudo ./zic -l fff = ==5528==ERROR: AddressSanitizer: global-buffer-overflow on address 0x0053103f at pc 0x00501ceb bp 0x7ffe9fb