reject entries with a zero compressed size on entry open - #447
Open
jmestwa-coder wants to merge 1 commit into
Open
reject entries with a zero compressed size on entry open#447jmestwa-coder wants to merge 1 commit into
jmestwa-coder wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Zero compressed size with a non-zero uncompressed size
A crafted archive that carries the real sizes in a zip64 extended-information field slips past miniz's consistency check (which only runs when neither 32-bit size field holds the sentinel), and its extractors then short-circuit the zero compressed size and return success without touching the output, so
zip_entry_readhands back 4000 bytes of untouched heap whilezip_entry_noallocreadreports 4000 into a 16-byte buffer it never wrote. Rejecting the inconsistent header at both read-mode opens covers the readers and the index-based delete path in one place, and keeps it apart from the directory guard in #441 which cannot reach this case;test_open_zero_comp_size_rejectedfails on master and passes here.