Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code.
| Software | From | Fixed in |
|---|---|---|
| postgresql / postgresql | 6.3.2 | 6.3.2.x |
| postgresql / postgresql | 7.1.1 | 7.1.1.x |
| postgresql / postgresql | 7.1.3 | 7.1.3.x |
| postgresql / postgresql | 7.0.3 | 7.0.3.x |
| postgresql / postgresql | 7.1 | 7.1.x |
| postgresql / postgresql | 6.5.3 | 6.5.3.x |
| postgresql / postgresql | 7.2.1 | 7.2.1.x |
| postgresql / postgresql | 7.1.2 | 7.1.2.x |