Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 698694 - app-arch/unzip-6.0_p25: test failure: error: invalid zip file with overlapped components (possible zip bomb)
Summary: app-arch/unzip-6.0_p25: test failure: error: invalid zip file with overlapped...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo's Team for Core System packages
URL: https://github.com/madler/unzip/issues/2
Whiteboard:
Keywords: TESTFAILURE
Depends on:
Blocks: CVE-2019-13232
  Show dependency tree
 
Reported: 2019-10-27 22:10 UTC by Thomas Deutschmann (RETIRED)
Modified: 2020-03-25 19:58 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
build.log (build.log,27.23 KB, text/plain)
2019-10-27 22:10 UTC, Thomas Deutschmann (RETIRED)
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Deutschmann (RETIRED) gentoo-dev 2019-10-27 22:10:04 UTC
Created attachment 594202 [details]
build.log

> >>> Test phase: app-arch/unzip-6.0_p25
> make --jobs 5 --load-average 7.95   check
> #####  This is a Unix-specific target.  (Just so you know.)
> #####     Make sure unzip, funzip and unzipsfx are compiled and
> #####     in this directory.
> #####  testing extraction
> Archive:  testmake.zip
>   inflating: testmake.zipinfo
> #####  testing zipinfo (unzip -Z)
> 1,4c1,3
> < Archive:  testmake.zip
> < Zip file size: 527 bytes, number of entries: 2
> < -rw-a--     2.3 ntf      126 tx defX 98-Nov-19 22:46 notes
> < -rw-a--     2.3 ntf      236 tx defX 98-Nov-19 22:46 testmake.zipinfo
> ---
> > Archive:  testmake.zip   527 bytes   2 files
> > -rw-a--     2.3 ntf      126 tx defX 19-Nov-98 22:46 notes
> > -rw-a--     2.3 ntf      236 tx defX 19-Nov-98 22:46 testmake.zipinfo
> #####  WARNING:  zipinfo output doesn't match stored version
> #####     (If the only difference is the file times, compare your
> #####      timezone with the Central European timezone, which is one
> #####      hour east of Greenwich but effectively 2 hours east
> #####      during summer Daylight Savings Time.  The upper two
> #####      lines should correspond to your local time when the
> #####      files were created, on 19 November 1998 at 10:46pm CET.
> #####      If the times are consistent, please ignore this warning.)
> #####  testing unzip -d exdir option
> Archive:  testmake.zip
>   inflating: testun/notes
> This file is part of testmake.zip for UnZip 5.4 and
> later.  It has DOS/OS2/NT style CR-LF line-endings.
> It's pretty short.
> #####  testing unzip -o and funzip (ignore funzip warning)
> funzip warning: zipfile has more than one entry--rest ignored
> #####  testing unzipsfx (self-extractor)
> UnZipSFX 6.00 of 20 April 2009, by Info-ZIP (http://www.info-zip.org).
> error: invalid zip file with overlapped components (possible zip bomb)
> make: *** [Makefile:501: check] Error 12



Portage 2.3.76 (python 3.6.9-final-0, default/linux/x86/17.0, gcc-8.3.0, glibc-2.29-r2, 4.19.72-gentoo-x86 i686)
=================================================================
System uname: Linux-4.19.72-gentoo-x86-i686-Intel-R-_Core-TM-_i7-3770K_CPU_@_3.50GHz-with-gentoo-2.6
KiB Mem:     3106552 total,   1951724 free
KiB Swap:     488276 total,    485964 free
Timestamp of repository gentoo: Sun, 27 Oct 2019 20:45:58 +0000
Head commit of repository gentoo: db01be01382eb338146df36c2dd6a15c6ddf9ebb

sh bash 4.4_p23-r1
ld GNU ld (Gentoo 2.32 p2) 2.32.0
app-shells/bash:          4.4_p23-r1::gentoo
dev-java/java-config:     2.2.0-r4::gentoo
dev-lang/perl:            5.28.2-r1::gentoo
dev-lang/python:          2.7.16::gentoo, 3.6.9::gentoo
dev-util/cmake:           3.14.6::gentoo
sys-apps/baselayout:      2.6-r1::gentoo
sys-apps/openrc:          0.41.2::gentoo
sys-apps/sandbox:         2.13::gentoo
sys-devel/autoconf:       2.13-r1::gentoo, 2.69-r4::gentoo
sys-devel/automake:       1.16.1-r1::gentoo
sys-devel/binutils:       2.32-r1::gentoo
sys-devel/gcc:            8.3.0-r1::gentoo
sys-devel/gcc-config:     2.0::gentoo
sys-devel/libtool:        2.4.6-r3::gentoo
sys-devel/make:           4.2.1-r4::gentoo
sys-kernel/linux-headers: 4.19::gentoo (virtual/os-headers)
sys-libs/glibc:           2.29-r2::gentoo
Repositories:

gentoo
    location: /usr/portage
    sync-type: git
    sync-uri: https://github.com/gentoo-mirror/gentoo.git
    priority: -1000

ABI="x86"
ABI_X86="32"
ACCEPT_KEYWORDS="x86"
ACCEPT_LICENSE="*"
ACCEPT_PROPERTIES="*"
ACCEPT_RESTRICT="*"
ADA_TARGET="gnat_2018"
ANT_HOME="/usr/share/ant"
ARCH="x86"
BROOT=""
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O2 -pipe -march=pentium4m -mtune=pentium4m -Wno-error=jump-misses-init -Wno-error=sign-compare"
CHOST="i686-pc-linux-gnu"
CHOST_x86="i686-pc-linux-gnu"
COLLISION_IGNORE="/lib/modules/*"
CONFIG_PROTECT="/etc /usr/share/config /usr/share/gnupg/qualified.txt"
CPU_FLAGS_X86="mmx mmxext sse sse2"
CXXFLAGS="-O2 -pipe -march=pentium4m -mtune=pentium4m -Wno-error=jump-misses-init -Wno-error=sign-compare"
DEFAULT_ABI="x86"
EDITOR="/usr/bin/mcedit"
ELIBC="glibc"
ENV_UNSET="DBUS_SESSION_BUS_ADDRESS DISPLAY GOBIN PERL5LIB PERL5OPT PERLPREFIX PERL_CORE PERL_MB_OPT PERL_MM_OPT XAUTHORITY XDG_CACHE_HOME XDG_CONFIG_HOME XDG_DATA_HOME XDG_RUNTIME_DIR"
EPREFIX=""
EROOT="/"
ESYSROOT="/"
FCFLAGS="-O2 -march=i686 -pipe"
FEATURES="assume-digests binpkg-docompress binpkg-dostrip binpkg-logs cgroup config-protect-if-modified distlocks downgrade-backup ebuild-locks fixlafiles ipc-sandbox merge-sync multilib-strict network-sandbox news parallel-fetch pid-sandbox preserve-libs protect-owned sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync xattr"
FFLAGS="-O2 -march=i686 -pipe"
GCC_SPECS=""
GRUB_PLATFORMS="efi-32 pc"
GSETTINGS_BACKEND="dconf"
HOME="/root"
INFOPATH="/usr/share/gcc-data/i686-pc-linux-gnu/8.3.0/info:/usr/share/binutils-data/i686-pc-linux-gnu/2.32/info:/usr/share/info"
INPUT_DEVICES="libinput keyboard mouse"
IUSE_IMPLICIT="abi_x86_32 prefix prefix-guest prefix-stack"
JAVAC="/etc/java-config-2/current-system-vm/bin/javac"
JAVA_HOME="/etc/java-config-2/current-system-vm"
JDK_HOME="/etc/java-config-2/current-system-vm"
KERNEL="linux"
L10N="en en-US de de-DE"
LANG="en_US.UTF-8"
LC_ALL="en_US.UTF-8"
LC_MESSAGES="C"
LC_PAPER="de_DE.UTF-8"
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
LIBDIR_x86="lib"
LINGUAS="en de"
LOGNAME="root"
MAIL="/var/mail/root"
MAKEOPTS="--jobs 5 --load-average 7.95"
MANPAGER="manpager"
MULTILIB_ABIS="x86"
NETBEANS_MODULES="apisupport cnd groovy gsf harness ide identity j2ee java mobility nb php profiler soa visualweb webcommon websvccommon xml"
NOCOLOR="true"
OFFICE_IMPLEMENTATION="libreoffice"
OLDPWD="/usr/portage"
OPENCL_PROFILE="ocl-icd"
OPENGL_PROFILE="xorg-x11"
PAGER="/usr/bin/less"
PATH="/usr/lib/llvm/8/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/opt/bin"
PHP_TARGETS="php7-1 php7-2 php7-3"
POSTGRES_TARGETS="postgres10 postgres11"
PWD="/usr/portage/app-arch/unzip"
PYTHONDONTWRITEBYTECODE="1"
PYTHON_SINGLE_TARGET="python3_6"
PYTHON_TARGETS="python2_7 python3_6"
QT_GRAPHICSSYSTEM="raster"
ROOT="/"
ROOTPATH="/usr/lib/llvm/8/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/opt/bin"
RUBY_TARGETS="ruby24 ruby25"
SHELL="/bin/bash"
SHLVL="2"
SSH_TTY="/dev/pts/0"
SYSROOT="/"
TERM="tmux-256color"
TMUX="/tmp//tmux-0/default,5222,0"
TMUX_PANE="%4"
TWISTED_DISABLE_WRITING_OF_PLUGIN_CACHE="1"
USER="root"
USERLAND="GNU"
VIDEO_CARDS="vmware"
XDG_CONFIG_DIRS="/etc/xdg"
XDG_DATA_DIRS="/usr/local/share:/usr/share"
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2019-10-27 22:19:36 UTC
Looks like an x86 problem. I am unable to reproduce on amd64.
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2019-10-28 00:08:35 UTC
Reported upstream.
Comment 3 Rolf Eike Beer archtester 2019-10-30 20:30:12 UTC
same on hppa
Comment 4 Alexey 2019-11-03 21:28:29 UTC
I've got this on arm.
Comment 5 ernsteiswuerfel archtester 2020-01-21 00:28:09 UTC
Same on ppc.
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-03-20 00:57:04 UTC
(In reply to Thomas Deutschmann from comment #2)
> Reported upstream.

Upstream claim this is now fixed:
https://github.com/madler/unzip/issues/2#issuecomment-583862515
>"Also take a look at the commit comments.
>You should make sure that those builds are using large file support."

Commit: https://github.com/madler/unzip/commit/13f0260beae851f7d5dd96e9ef757d8d6d7daac1
Comment 7 Thomas Deutschmann (RETIRED) gentoo-dev 2020-03-20 00:59:34 UTC
I have seen this but for yet unknown reason I have lost my reproducer (i.e. app-arch/unzip-6.0_p25 doesn't fail anymore) so I cannot really verify.
Comment 8 Rolf Eike Beer archtester 2020-03-25 19:50:24 UTC
Can still reproduce this on hppa, and the patch fixes it.
Comment 9 Larry the Git Cow gentoo-dev 2020-03-25 19:58:37 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=26dd0be6dc420c5e4c4067fa60bd465fa23d0571

commit 26dd0be6dc420c5e4c4067fa60bd465fa23d0571
Author:     Thomas Deutschmann <whissi@gentoo.org>
AuthorDate: 2020-03-25 19:56:42 +0000
Commit:     Thomas Deutschmann <whissi@gentoo.org>
CommitDate: 2020-03-25 19:58:30 +0000

    app-arch/unzip: fix false overlapped components detection on 32-bit systems
    
    Closes: https://bugs.gentoo.org/698694
    Package-Manager: Portage-2.3.94, Repoman-2.3.21
    Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>

 ...-false-overlap-detection-on-32bit-systems.patch | 50 ++++++++++++++++++++++
 ...nzip-6.0_p25.ebuild => unzip-6.0_p25-r1.ebuild} |  1 +
 2 files changed, 51 insertions(+)