[tz] buffer overflow in zic

2025-03-05 Thread Evgeniy Gorbanev via tz
Hello! IfoundthatifI runzictocreatea linkonanotherdevice, the bufferoverflowinzip.c:1422inversion2025awill occur. Inthislinei==0. The commandtoreplay: ./zic -l test -d . -t /path/to/link_on_another_device Best regards, Evgeniy Gorbanyov

[tz] Re: buffer overflow in zic

2025-03-05 Thread Paul Eggert via tz
On 2025-03-04 22:12, Evgeniy Gorbanev via tz wrote: Hello! IfoundthatifI runzictocreatea linkonanotherdevice, the bufferoverflowinzip.c:1422inversion2025awill occur. Inthislinei==0. The commandtoreplay: ./zic -l test -d . -t /path/to/ link_on_another_device Best regards, Evgeniy Gorbanyov Un

[tz] Re: buffer overflow in zic

2025-03-05 Thread Clive D.W. Feather via tz
Paul Eggert via tz said: > On 2025-03-04 22:12, Evgeniy Gorbanev via tz wrote: > > Hello! > > > > IfoundthatifI runzictocreatea linkonanotherdevice, the > > bufferoverflowinzip.c:1422inversion2025awill occur. Inthislinei==0. > > The commandtoreplay: ./zic -l test -d . -t /path/to/ > > link_on_anot

[tz] Re: buffer overflow in zic

2025-03-05 Thread Guy Harris via tz
On Mar 4, 2025, at 10:12 PM, Evgeniy Gorbanev via tz wrote: > I found that if I run zic to create a link on another device, the buffer > overflow in zip.c:1422 in version 2025a will occur. In this line i == 0. I.e., if "target" is an empty string, it won't work.

[tz] Re: buffer overflow in zic

2025-03-05 Thread Guy Harris via tz
On Mar 5, 2025, at 11:34 AM, Paul Eggert via tz wrote: > On 2025-03-04 22:12, Evgeniy Gorbanev via tz wrote: >> Hello! >> >> I found that if I run zic to create a link on another device, the buffer >> overflow in zip.c:1422 in version 2025a will occur. In this line i == 0. >> >> The command to