Bug #81490 [PATCH]: ZipArchive::extractTo() may leak memory
| From: | cmb@php.net | Date: | Thu, 30 Sep 2021 11:54:04 +0000 |
| Subject: | Bug #81490 [PATCH]: ZipArchive::extractTo() may leak memory | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-236935@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81490&edit=1
ID: 81490
Patch added by: cmb@php.net
Reported by: cmb@php.net
Summary: ZipArchive::extractTo() may leak memory
Status: Assigned
Type: Bug
Package: Zip Related
Operating System: *
PHP Version: 7.4Git-2021-09-30 (Git)
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
The following pull request has been associated:
Patch Name: Fix #81490: ZipArchive::extractTo() may leak memory
On GitHub: https://github.com/php/php-src/pull/7536
Patch: https://github.com/php/php-src/pull/7536.patch
Previous Comments:
------------------------------------------------------------------------
[2021-09-30 11:44:35] cmb@php.net
Description:
------------
ZIP archives may contain files with an empty filename[1]:
| If input came from standard input, the file name length is set
| to zero.
If such a file is extracted, there is a memory leak. The same
happens whenever virtual_file_ex() fails for the given filename,
for whatever reason.
[1] <https://pkware.cachefly.net/webdocs/casestudies/APPNOTE.TXT>
section 4.4.12
Test script:
---------------
<?php
$zip = new ZipArchive();
$zip->open(__DIR__ . "/test.zip", ZipArchive::CREATE|ZipArchive::OVERWRITE);
$zip->addFromString("", "yada yada");
mkdir(__DIR__ . "/extract");
$zip->open(__DIR__ . "/test.zip");
$zip->extractTo(__DIR__ . "/extract", "");
?>
Actual result:
--------------
[Thu Sep 30 13:42:44 2021] Script: 'C:\php-sdk\phpdev\vc15\x64\zip1.php'
ext\zip\php_zip.c(154) : Freeing 0x0000023abbe88000 (1 bytes),
script=C:\php-sdk\phpdev\vc15\x64\zip1.php
=== Total 1 memory leaks detected ===
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81490&edit=1