Repository navigation
Zipfile lib overwrites the extra field during closing when the archive size is more then ZIP64_LIMIT #88233
Copy link
Copy link
Closed
Labels
3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixes3.7 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of lifestdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
Description
Activity
The current zipFile implementation supports the allowZip64,which can make large zip files.
There is a bug in the current implementation of close method, where the extra field is overwritten.To reproduce it:
- Create a directory with more then 4 GB of data(spread over many files).
- Make the zip of those files using the any rar achiever which adds NTFS metadata (mtime, atime, and ctime) of files in the zip.
- Append a new file to the zip using the zip library .
When I open the zip again, the files processed after the ZIP64_LIMIT is reached will have their extra fields overwritten.
I have attached the zip that contained the python used to add the new file and the images of zip archive before adding new files and after.
- added3.7 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of life3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixesstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on May 7, 2021 11 remaining items
- moved this to Done in @serhiy-storchaka's project python-zipfile
on Feb 20, 2023 - added 4 commits that reference this issue
on Feb 20, 2023 - added 2 commits that reference this issue
on Feb 20, 2023 - added a commit that references this issue
on Sep 25, 2023
Metadata
Metadata
Assignees
Labels
3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixes3.7 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of lifestdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
Projects
- StatusShow more project fieldsDone
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields:
Linked PRs