changeset: 103779:5ae8756a1ae0 branch: 3.3 parent: 102713:8e3b9bf917a7 user: Berker Peksag date: Wed Sep 14 08:37:28 2016 +0300 files: Misc/NEWS Modules/zipimport.c description: Issue #26171: Prevent buffer overflow in get_data Backport of 01ddd608b85c. diff -r 8e3b9bf917a7 -r 5ae8756a1ae0 Misc/NEWS --- a/Misc/NEWS Tue Aug 16 23:35:35 2016 -0700 +++ b/Misc/NEWS Wed Sep 14 08:37:28 2016 +0300 @@ -10,6 +10,9 @@ Core and Builtins ----------------- +- Issue #26171: Fix possible integer overflow and heap corruption in + zipimporter.get_data(). + - Issue #25709: Fixed problem with in-place string concatenation and utf-8 cache. - Issue #24407: Fix crash when dict is mutated while being updated. diff -r 8e3b9bf917a7 -r 5ae8756a1ae0 Modules/zipimport.c --- a/Modules/zipimport.c Tue Aug 16 23:35:35 2016 -0700 +++ b/Modules/zipimport.c Wed Sep 14 08:37:28 2016 +0300 @@ -1089,6 +1089,11 @@ PyMarshal_ReadShortFromFile(fp); /* local header size */ file_offset += l; /* Start of file data */ + if (data_size > LONG_MAX - 1) { + fclose(fp); + PyErr_NoMemory(); + return NULL; + } bytes_size = compress == 0 ? data_size : data_size + 1; if (bytes_size == 0) bytes_size++;