Integer overflow in the __tzfile_read function in glibc...
        
  Moderate severity
        
          Unreviewed
      
        Published
          May 2, 2022 
          to the GitHub Advisory Database
          •
          Updated Apr 11, 2025 
      
  
Description
        Published by the National Vulnerability Database
      May 2, 2013 
    
  
        Published to the GitHub Advisory Database
      May 2, 2022 
    
  
        Last updated
      Apr 11, 2025 
    
  
Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.
References