changeset: 100015:01ddd608b85c branch: 3.4 parent: 100012:eb19459ce46a user: Benjamin Peterson date: Wed Jan 20 22:23:44 2016 -0800 files: Misc/NEWS Modules/zipimport.c description: prevent buffer overflow in get_data (closes #26171) diff -r eb19459ce46a -r 01ddd608b85c Misc/NEWS --- a/Misc/NEWS Wed Jan 20 22:06:43 2016 -0800 +++ b/Misc/NEWS Wed Jan 20 22:23:44 2016 -0800 @@ -10,6 +10,9 @@ Core and Builtins ----------------- +- Issue #26171: Fix possible integer overflow and heap corruption in + zipimporter.get_data(). + Library ------- diff -r eb19459ce46a -r 01ddd608b85c Modules/zipimport.c --- a/Modules/zipimport.c Wed Jan 20 22:06:43 2016 -0800 +++ b/Modules/zipimport.c Wed Jan 20 22:23:44 2016 -0800 @@ -1111,6 +1111,11 @@ } file_offset += l; /* Start of file data */ + if (data_size > LONG_MAX - 1) { + fclose(fp); + PyErr_NoMemory(); + return NULL; + } bytes_size = compress == 0 ? data_size : data_size + 1; if (bytes_size == 0) bytes_size++;