Bug #77565 [Ver->Csd]: Incorrect locator detection in ZIP-based phars
| From: | cmb@php.net | Date: | Tue, 05 Jan 2021 22:47:35 +0000 |
| Subject: | Bug #77565 [Ver->Csd]: Incorrect locator detection in ZIP-based phars | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-231382@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77565&edit=1
ID: 77565
Updated by: cmb@php.net
Reported by: tshumbeo at mailhouse dot biz
Summary: Incorrect locator detection in ZIP-based phars
-Status: Verified
+Status: Closed
Type: Bug
Package: PHAR related
Operating System: Any
PHP Version: 7.3.1
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=d1b1c043988277b7c0d46ec7c953418cbfbb2608
Log: Fix #77565: Incorrect locator detection in ZIP-based phars
Previous Comments:
------------------------------------------------------------------------
[2020-12-11 14:36:10] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #77565: Incorrect locator detection in ZIP-based phars
On GitHub: https://github.com/php/php-src/pull/6507
Patch: https://github.com/php/php-src/pull/6507.patch
------------------------------------------------------------------------
[2019-02-04 12:47:24] tshumbeo at mailhouse dot biz
Description:
------------
phar_parse_zipfile() is looking for the end of central directory (phar_zip_dir_end locator) by going
from the file's beginning to the end, stopping at the first occurrence. Due to this, it may
locate a sequence that looks like EOCD but is not one. Instead, it should go from the end of the
file or, at very least, postpone decision about the locator until the entire stream is traversed,
and use the last occurrence (which is in accordance with the spec).
As of now, Phar is unable to open a ZIP archive that contains another ZIP archive inside, or a
similarly looking file, and is not deflated.
Test script:
---------------
# mkdir test
# cd test
# touch file
# zip 1.zip file
adding: file (stored 0%)
# zip 2.zip 1.zip
adding: 1.zip (stored 0%)
# php -r 'new PharData("1.zip"); echo "ok";'
ok
# php -r 'new PharData("2.zip");'
PHP Fatal error: Uncaught UnexpectedValueException: phar error: corrupted central directory entry,
no magic signature in zip-based phar "/tmp/test/2.zip" in Command line code:1
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77565&edit=1