Skip to content

route zip archives by all valid PK signatures - #46

Open
abdul-khaliq-khalid wants to merge 1 commit into
google:mainfrom
abdul-khaliq-khalid:zip-signature-routing
Open

route zip archives by all valid PK signatures#46
abdul-khaliq-khalid wants to merge 1 commit into
google:mainfrom
abdul-khaliq-khalid:zip-signature-routing

Conversation

@abdul-khaliq-khalid

Copy link
Copy Markdown

security_scan routes an input to the zip scanner only when it starts with the b"PK\x03\x04" local-file-header magic, but utils.is_zip_bytes already treats b"PK\x05\x06" and b"PK\x07\x08" as zips too. zipfile reads the central directory at the end of the file, so it happily opens an archive that begins with the spanned-archive marker b"PK\x07\x08", and a malicious pickle inside one is never handed to _extract_and_scan_archive: the same payload scores unsafe=3 in a normal zip and unsafe=0 once the marker is prepended. I pulled the signature list into constants.ZIP_MAGIC_BYTES so is_zip_bytes and every routing site agree on what counts as a zip.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant