changeset: 100018:2df462852464 parent: 100014:e82fb1d2febb parent: 100017:10dad6da1b28 user: Benjamin Peterson date: Wed Jan 20 22:25:40 2016 -0800 files: Misc/NEWS Modules/zipimport.c description: merge 3.5 (#26171) diff -r e82fb1d2febb -r 2df462852464 Misc/NEWS --- a/Misc/NEWS Wed Jan 20 22:07:50 2016 -0800 +++ b/Misc/NEWS Wed Jan 20 22:25:40 2016 -0800 @@ -140,6 +140,9 @@ converted to normal strings at run time. Given x=3, then f'value={x}' == 'value=3'. Patch by Eric V. Smith. +- Issue #26171: Fix possible integer overflow and heap corruption in + zipimporter.get_data(). + Library ------- diff -r e82fb1d2febb -r 2df462852464 Modules/zipimport.c --- a/Modules/zipimport.c Wed Jan 20 22:07:50 2016 -0800 +++ b/Modules/zipimport.c Wed Jan 20 22:25:40 2016 -0800 @@ -1127,6 +1127,11 @@ } file_offset += l; /* Start of file data */ + if (data_size > LONG_MAX - 1) { + fclose(fp); + PyErr_NoMemory(); + return NULL; + } bytes_size = compress == 0 ? data_size : data_size + 1; if (bytes_size == 0) bytes_size++;