Skip to content

Commit 6e3e91f

Browse files
miss-islingtoncmaloneydanifusblurb-it[bot]
authored
[3.12] gh-113977, gh-120754: Remove unbounded reads from zipfile (GH-122101) (#126347)
gh-113977, gh-120754: Remove unbounded reads from zipfile (GH-122101) GH-113977, GH-120754: Remove unbounded reads from zipfile Read without a size may read an unbounded amount of data + allocate unbounded size buffers. Move to capped size reads to prevent potential issues. (cherry picked from commit 556dc9b) Co-authored-by: Cody Maloney <[email protected]> Co-authored-by: Daniel Hillier <[email protected]> Co-authored-by: blurb-it[bot] <43283697+blurb-it[bot]@users.noreply.github.com>
1 parent 4afa129 commit 6e3e91f

File tree

2 files changed

+4
-3
lines changed

2 files changed

+4
-3
lines changed

Lib/zipfile/__init__.py

+3-3
Original file line numberDiff line numberDiff line change
@@ -295,7 +295,7 @@ def _EndRecData(fpin):
295295
fpin.seek(-sizeEndCentDir, 2)
296296
except OSError:
297297
return None
298-
data = fpin.read()
298+
data = fpin.read(sizeEndCentDir)
299299
if (len(data) == sizeEndCentDir and
300300
data[0:4] == stringEndArchive and
301301
data[-2:] == b"\000\000"):
@@ -315,9 +315,9 @@ def _EndRecData(fpin):
315315
# record signature. The comment is the last item in the ZIP file and may be
316316
# up to 64K long. It is assumed that the "end of central directory" magic
317317
# number does not appear in the comment.
318-
maxCommentStart = max(filesize - (1 << 16) - sizeEndCentDir, 0)
318+
maxCommentStart = max(filesize - ZIP_MAX_COMMENT - sizeEndCentDir, 0)
319319
fpin.seek(maxCommentStart, 0)
320-
data = fpin.read()
320+
data = fpin.read(ZIP_MAX_COMMENT + sizeEndCentDir)
321321
start = data.rfind(stringEndArchive)
322322
if start >= 0:
323323
# found the magic number; attempt to unpack and interpret
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
Update unbounded ``read`` calls in :mod:`zipfile` to specify an explicit ``size`` putting a limit on how much data they may read. This also updates handling around ZIP max comment size to match the standard instead of reading comments that are one byte too long.

0 commit comments

Comments
 (0)