oss-sec mailing list archives

unzip -t crasher


From: Jakub Wilk <jwilk () jwilk net>
Date: Sun, 2 Nov 2014 19:06:40 +0100

Latest American fuzzy lop[0] tarball[1] contains a zip file that crashes unzip -t:

$ unzip -qt afl-0.43b/docs/samples/unzip_t_malloc.zip
foo/:  mismatching "local" filename (™/UT),
        continuing with "central" filename version
*** Error in `unzip': free(): corrupted unsorted chunks: 0x00000000015d0170 ***

I'm not sure if inclusion of said zip file was intentional, but since the cat is already out of the bag, I thought I'll let you know.

[0] https://code.google.com/p/american-fuzzy-lop/
[1] http://lcamtuf.coredump.cx/afl.tgz

--
Jakub Wilk


Current thread: