#952509 zipnote : Segfault during write operation

Package:
zip
Source:
zip
Description:
Archiver for .zip files
Submitter:
koala
Date:
2025-04-22 22:33:03 UTC
Severity:
normal
#952509#5
Date:
2020-02-25 07:51:28 UTC
From:
To:
Version: 3.0-11+b1

Dear Maintainer,

I would like to report a security bug to zipnote binary of zip package (zipinfo).

A segfault during the write operation with zipnote version 3.0

How to reproduce the bug :

1 - zipnote crash00.zip > note

2 - zipnote -w crash00.zip < note

The execution trace show a memcpy with the wrong size :

######################################

free(0x559aff234480)                                                                                            = <void>

free(0x559aff2343a0)                                                                                            = <void>

fclose(0x559aff234150)                                                                                          = 0

ftello64(0x559aff233280, 1, 0, 0x559aff233010)                                                                  = 124

malloc(1)                                                                                                       = 0x559aff234480

memcpy(0x559aff234480, "", 0)                                                                                   = 0x559aff234480

memcpy(0x559aff234480, "mples/UT\005\0\177\0\0\0\0\0\0\0\0\0\0\301\0\0\0\0\0\0\0\036\003\n"..., 18446744073709551605 <no return ...>
--- SIGSEGV (Segmentation fault) ---

######################################

I stay available if you need more informations.

Best regards.

The version of zipnote :

'''''''''''''''''''''''''''''''''''''

$ zipnote -v

Copyright (c) 1990-2008 Info-ZIP - Type 'zipnote "-L"' for software license.

This is ZipNote 3.0 (July 5th 2008), by Info-ZIP.

Currently maintained by E. Gordon.  Please send bug reports to

the authors using the web page at www.info-zip.org; see README for details.

Latest sources and executables are at ftp://ftp.info-zip.org/pub/infozip,

as of above date; see http://www.info-zip.org/ for other sites.

Compiled with gcc 6.3.0 20170221 for Unix (Linux ELF).

ZipNote special compilation options:

        [none]

The version of debian :

'''''''''''''''''''''''''''''''''''''

Linux 4.19.0-5-cloud-amd64 #1 SMP Debian 4.19.37-5+deb10u2 (2019-08-08) x86_64 GNU/Linux

The file :

'''''''''''''''''''''''''''''''''''''

$ hexdump -C crash00.zip

00000000  50 4b 03 04 0a 00 00 00  0a 00 3c 69 25 50 00 00  |PK........<i%P..|

00000010  00 00 00 00 00 1c 00 94  00 00 09 00 02 00 2d 00  |..............-.|

00000020  32 6d 70 6c 65 73 2f 55  54 09 00 03 74 26 12 5e  |2mples/UT...t&.^|

00000030  82 26 12 5e 75 78 0b 00  01 04 e9 03 00 00 04 e9  |.&.^ux..........|

00000040  03 00 00 50 4b 01 02 1e  03 0a 00 00 00 00 00 3c  |...PK..........<|

00000050  69 25 50 00 00 00 00 00  00 00 00 ff ff ff ff 29  |i%P............)|

00000060  00 18 00 00 00 00 00 00  00 10 00 ed 4f 00 00 00  |............O...|

00000070  00 65 78 61 6d 70 6c 65  73 2f 55 54 05 00 03 74  |.examples/UT...t|

00000080  26 12 5e 90 6c 0b 00 01  04 e9 03 00 00 04 e9 03  |&.^.l...........|

00000090  00 00 50 4b 05 06 00 00  00 00 01 00 1f 00 4f 00  |..PK..........O.|

000000a0  f5 bf 8d 2c e3 83 9b 2c  e3 83 9d 2c e3 82 bb 2c  |...,...,...,...,|

000000b0  2c e3 83 9f 2c e3 83 8f  40 e3 83 98 2c 2c 2c e3  |,...,...@...,,,.|

000000c0  83 8a 5d 3d 5b 21 21 e3  82 a6 5d 2b 21 e3 82 a6  |..]=[!!...]+!...|

000000d0  2b e3 82 a6 2e e3 82 a6  29 5b e3 82 a2 2b 3d e3  |+.......)[...+=.|

000000e0  82 a6 2b e3 83 8a 2b e3  83 98 2b e3 83 8d 2b e3  |..+...+...+...+.|

000000f0  83 9b 2b e3 99 8c 2b e3  82 a2 2b e3 83 8d 2b e3  |..+...+...+...+.|

00000100  00 00 50 4b 01 02 1e 03  0a 00 00 00 00 00 3c 69  |..PK..........<i|

00000110  25 50 00 00 00 00 00 00  00 00 ff ff ff ff 29 00  |%P............).|

00000120  18 00 00 00 00 00 00 00  10 00 ed 43 00 00 00 00  |...........C....|

00000130  65 78 61 6d 70 6c 65 73  00 00 04 e9 03 00 00 50  |examples.......P|

00000140  4b 05 06 00 00 00 00 01  00 01 00 4f 00 f5 83 8d  |K..........O....|

00000150  2c e3 83 9b 2c e3 83 8c  2c e3 82 bb 2c 2c e3 83  |,...,...,...,,..|

00000160  9f 2c e3 83 8f 2c e3 83  98 2c 2c 2c e3 83 8a 5d  |.,...,...,,,...]|

00000170  3d 5b 21 21 e3 82 a6 5d  2b 21 e3 82 a6 2b e3 82  |=[!!...]+!...+..|

00000180  03 03 03 03 03 03 03 03  03 03 03 03 03 03 03 03  |................|

*

000001c0  00 01 03 03 03 03 03 03  00 00 00 1b 69 25 50 00  |............i%P.|

000001d0  00 3d 3d 3d 3d 3d 3d 3d  3d 3d 3d 3d 3d 3d 3d 3d  |.===============|

000001e0  3d 3d 3d 3d 3d 00 00 00  00 00 00 00 00 ff eb 78  |=====..........x|

000001f0  0b 00 01 04 e9 03 00 00  04 e9 03 00 01 50 4b 05  |.............PK.|

00000200  06 00 ef 50 4b 01 03 00  00 04 e9 03 00 01 50 4b  |...PK.........PK|

00000210  05 06 00 00 00 00 01 00  02 00 74 26 00 00 43 00  |..........t&..C.|

00000220  00 00 a7 00 40 20 28 5b  2c e3 82 a6 2c 2c 2c 2c  |....@ ([,...,,,,|

00000230  e3 82 bf 5d 3d 5b 5d 2b  7b 7d 2c 5b e3 83 8d 2c  |...]=[]+{},[...,|

00000240  e3 83 9b 3e e3 83 8c 2c  e3 82 bb 2c 2c e3 83 9f  |...>...,...,,...|

00000250  2c e3 83 8f 2c e3 83 98  2c 2c 2c e3 83 8a 5d 3d  |,...,...,,,...]=|

00000260  5b 21 21 e3 82 a6 5d 2b  21 e3 82 a6 2b e3 82 a6  |[!!...]+!...+...|

00000270  2e e3 82 a6 29 5b e3 82  a2 2b 3d e3 82 a6 2b e3  |....)[...+=...+.|

00000280  83 8a 2b e3 83 98 2b e3  83 8d 2b e3 83 9b 2b e3  |..+...+...+...+.|

00000290  83 8c 2b e3 82 a2 2b e3  00 00 00 00 00 00 00 00  |..+...+.........|

000002a0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|

*

000002c0  80 00 00 00 00 00 00 00  00 00 00 00 00 00        |..............|

000002ce

#952509#14
Date:
2020-03-10 12:07:57 UTC
From:
To:
Thanks for the report. I've just reassigned it to the "zip" package,
where it really belongs (you can tell by doing "dpkg -S /usr/bin/zipnote")

Could you please attach the file itself, instead of providing an
hexdump? That would make things easier for everybody.

Then I'll try to forward this upstream.

Thanks.

#952509#19
Date:
2020-09-28 10:04:09 UTC
From:
To:
Dear Maintainer,
I tried to convert the hexdump into attached binary and it produces on
the "zipnote -w crash00.zip < note" plenty lines as these with a final
segmentation fault.

    ...
    zipnote error: Interrupted (aborting)
    free(): double free detected in tcache 2

    Speicherzugriffsfehler

Running in a debugger, the first segfault happens here:

    (rr) bt
    #0  __memmove_avx_unaligned_erms () at ../sysdeps/x86_64/multiarch/memmove-vec-unaligned-erms.S:535
    #1  0x000055fcb8f85ae0 in memcpy (__len=<optimized out>, __src=0x55fcb9d21b03, __dest=0x55fcb9d22040) at /usr/include/x86_64-linux-gnu/bits/string3.h:53
    #2  add_central_zip64_extra_field (pZipListEntry=0x55fcb9d219e0) at zipfile.c:1192
    #3  putcentral (z=0x55fcb9d219e0) at zipfile.c:5667
    #4  0x000055fcb8f80cc8 in main (argc=<optimized out>, argv=<optimized out>) at zipnote.c:670

This is tried to be handled in function "handler", which tries
to free some memory, which glibc tries to abort the process,
which is handled again in "handler" ...
Until stack is exhausted and process crashes finally.
That second recursive issue might be avoided by restoring
the default signal handling when "handler" is executed?

    (rr) bt
    #0  __GI_raise (sig=sig@entry=6) at ../sysdeps/unix/sysv/linux/raise.c:50
    #1  0x00007ffadb927537 in __GI_abort () at abort.c:79
    #2  0x00007ffadb980828 in __libc_message (action=action@entry=do_abort, fmt=fmt@entry=0x7ffadba8ee31 "%s\n") at ../sysdeps/posix/libc_fatal.c:155
    #3  0x00007ffadb987b1a in malloc_printerr (str=str@entry=0x7ffadba91170 "free(): double free detected in tcache 2") at malloc.c:5347
    #4  0x00007ffadb989115 in _int_free (av=0x7ffadbac0b80 <main_arena>, p=0x55fcb9d212e0, have_lock=0) at malloc.c:4201
    #5  0x00007ffadb9763bf in _IO_deallocate_file (fp=0x55fcb9d212f0) at libioP.h:863
    #6  _IO_new_fclose (fp=0x55fcb9d212f0) at iofclose.c:74
    #7  0x000055fcb8f814b8 in ziperr (c=9, h=<optimized out>) at zipnote.c:162
    #8  0x000055fcb8f81536 in handler (s=<optimized out>) at zipnote.c:181
    #9  <signal handler called>
    #10 __GI_raise (sig=sig@entry=6) at ../sysdeps/unix/sysv/linux/raise.c:50
    #11 0x00007ffadb927537 in __GI_abort () at abort.c:79
    #12 0x00007ffadb980828 in __libc_message (action=action@entry=do_abort, fmt=fmt@entry=0x7ffadba8ee31 "%s\n") at ../sysdeps/posix/libc_fatal.c:155
    #13 0x00007ffadb987b1a in malloc_printerr (str=str@entry=0x7ffadba91210 "double free or corruption (out)") at malloc.c:5347
    #14 0x00007ffadb989148 in _int_free (av=0x7ffadbac0b80 <main_arena>, p=0x55fcb9d21cb0, have_lock=<optimized out>) at malloc.c:4314
    #15 0x000055fcb8f814d5 in ziperr (c=9, h=<optimized out>) at zipnote.c:166
    #16 0x000055fcb8f81536 in handler (s=<optimized out>) at zipnote.c:181
    #17 <signal handler called>
    #18 __memmove_avx_unaligned_erms () at ../sysdeps/x86_64/multiarch/memmove-vec-unaligned-erms.S:535
    #19 0x000055fcb8f85ae0 in memcpy (__len=<optimized out>, __src=0x55fcb9d21b03, __dest=0x55fcb9d22040) at /usr/include/x86_64-linux-gnu/bits/string3.h:53
    #20 add_central_zip64_extra_field (pZipListEntry=0x55fcb9d219e0) at zipfile.c:1192
    #21 putcentral (z=0x55fcb9d219e0) at zipfile.c:5667
    #22 0x000055fcb8f80cc8 in main (argc=<optimized out>, argv=<optimized out>) at zipnote.c:670

Kind regards,
Bernhard