Thread: Re: Buffer overflow in zic

Re: Buffer overflow in zic

From
Tom Lane
Date:
Evgeniy Gorbanyov <gorbanyoves@basealt.ru> writes:
> Ifyou compilezicwithASAN,you cangetthe following(notethiswill 
> delete/etc/localtime):
> |$ sudo ./zic -l fff

zic is not our code.  Please take this up with the upstream IANA
list tz@iana.org.  (They might want to see a reproducer against
their current code ... we're a bit behind on syncing that.)

https://www.iana.org/time-zones

            regards, tom lane