Skip to content

ZipInputStream.GetNextEntry hangs permanently #300

Description

@Metalnem

ZipInputStream.GetNextEntry hangs permanently when attempting to extract the attached archive. I'm using the latest SharpZipLib NuGet package (version 1.1.0). You can run the following code to reproduce it (the path variable should contain the path to the attached file):

using (var file = File.OpenRead(path))
using (var zip = new ZipInputStream(file))
{
  while (zip.GetNextEntry() != null) { }
}

Found via SharpFuzz.

Activity

  1. Numpsy commented on Jan 20, 2019

    @Numpsy
    Contributor

    Looks to be getting stuck @ https://github.com/icsharpcode/SharpZipLib/blob/master/src/ICSharpCode.SharpZipLib/Zip/ZipInputStream.cs#L372, where Read() constantly returns more data.

    Possibly related to #128 / #88 / #19 ?

  2. piksel commented on Jan 27, 2019

    @piksel
    Member

    My analysis so far is that the dynamic tree for the "bad" block assigns code length 0 to symbol 255. This is supposed to indicate that symbol 255 is not present in block. So when we're inflating the block and find a 255 we're moving the input buffer along 0 bits (the code length) and output a 0 byte. This obviously leads to an infinite loop since the input pointer is never incremented.
    The shortest valid code length is 1, so I think we can throw an exception in GetSymbol if the code length (symbol & 15) is less than one.

  3. piksel commented on Jul 29, 2019

    @piksel
    Member

    Fixed by #316.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugzipRelated to ZIP file format

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions