Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

minizip: Check length of comment, filename, and extra field, in zipOpenNewFileInZip4_64 #843

Closed
wants to merge 1 commit into from

Commits on Aug 18, 2023

  1. minizip: Check length of comment, filename, and extra field, in zipOp…

    …enNewFileInZip4_64
    
    These are stored in 16-bit fields in the zip file format. Passing longer
    values would generate an invalid file.
    
    Passing very long values could also cause the computation of
    zi->ci.size_centralheader to overflow, which would cause heap buffer
    overflow on subsequent writes to zi->ci.central_header.
    zmodem committed Aug 18, 2023
    Configuration menu
    Copy the full SHA
    431e663 View commit details
    Browse the repository at this point in the history