Commit Graph

2601 Commits

Author SHA1 Message Date
Adam Hathcock
5fdae1cf82 Make readonly and fix visibility 2018-05-05 19:23:34 +01:00
Adam Hathcock
9e892ab397 Merge pull request #376 from leezer3/master
Fix broken link in usage.md
2018-05-05 16:18:17 +01:00
Christopher Lees
e95559b4fc Fix broken link in usage.md 2018-05-05 15:08:56 +01:00
Adam Hathcock
18475cc86d Use proper xunit single threading 2018-05-05 09:38:56 +01:00
Adam Hathcock
88b59600cd Merge pull request #369 from adamhathcock/leaveOpen
Rework LeaveOpen to be consistent
2018-05-05 09:27:32 +01:00
Adam Hathcock
9a9d64bcbe Merge branch 'master' into leaveOpen
# Conflicts:
#	src/SharpCompress/Compressors/LZMA/LZipStream.cs
2018-05-05 09:25:26 +01:00
Adam Hathcock
4f3408ec25 Merge pull request #375 from adamhathcock/issue_360
Fixes lzip stream disposal
2018-05-05 09:20:35 +01:00
Adam Hathcock
e9d0fb85ac Merge branch 'master' into leaveOpen 2018-05-05 09:19:38 +01:00
Adam Hathcock
1ce37ef7a8 Fixes lzip stream disposal 2018-05-05 09:18:01 +01:00
Adam Hathcock
ecad356e30 Merge pull request #363 from sridhar6668/sridhar6668/support_extended_ascii
ZipArchive Reader: Uses IBM PC character encoding to decode filename …
2018-05-05 09:12:22 +01:00
Adam Hathcock
fafd8da91d Merge branch 'master' into leaveOpen 2018-05-05 09:10:19 +01:00
Adam Hathcock
2fb31d4b84 Merge branch 'master' into sridhar6668/support_extended_ascii 2018-05-05 09:09:09 +01:00
Adam Hathcock
8b478451ac Evil zip is a windows only test because of paths 2018-05-05 09:05:32 +01:00
Adam Hathcock
42b1205fb4 Merge pull request #374 from odinn1984/feat/fail_on_outside_target_files
fix: prevent extracting archived files outside of target path
2018-05-02 22:51:02 +01:00
odinn1986
80ceb1c375 fix: prevent extracting archived files outside of target path
This PR is meant to fix an arbitrary file write vulnerability, that can be
achieved using a specially crafted zip archive, that holds path traversal
filenames. When the filename gets concatenated to the target extraction
directory, the final path ends up outside of the target folder.

A sample malicious zip file named Zip.Evil.zip was used,
and when running the code below, resulted in the creation of C:/Temp/evil.txt
outside of the intended target directory.

There are various possible ways to avoid this issue, some include checking
for .. (dot dot) characters in the filename, but the best solution in our
opinion is to check if the final target filename, starts with the target
folder (after both are resolved to their absolute path).

Stay secure,
Snyk Team
2018-05-02 23:12:33 +03:00
Adam Hathcock
501407c3fe Change flag name to be closer to spec 2018-04-29 16:33:15 +01:00
Adam Hathcock
abddabf18e Proper fixes for all platforms 2018-04-29 16:27:26 +01:00
Adam Hathcock
91d753cbdb Merge branch 'master' into sridhar6668/support_extended_ascii 2018-04-29 15:12:02 +01:00
Adam Hathcock
259acd0694 misc additions 2018-04-29 15:09:26 +01:00
Adam Hathcock
33f7258ea2 Merge branch 'master' into leaveOpen
# Conflicts:
#	src/SharpCompress/Common/Rar/Headers/RarHeaderFactory.cs
#	src/SharpCompress/Readers/Rar/RarReader.cs
2018-04-29 14:47:08 +01:00
Adam Hathcock
1ea7bb57e5 Merge branch 'master' into sridhar6668/support_extended_ascii 2018-04-29 11:39:09 +01:00
Adam Hathcock
3e60e796fb Merge pull request #340 from adamhathcock/rar5
Rar5 Feature
2018-04-29 11:36:49 +01:00
Adam Hathcock
d9c178cbee Fix all platform support 2018-04-29 11:33:49 +01:00
Adam Hathcock
031b3c55f6 FIx solid support. I did it wrong 2018-04-29 11:12:28 +01:00
Adam Hathcock
b43d2c3d95 Disabled decryption tests 2018-04-29 10:55:51 +01:00
Adam Hathcock
d865120480 ArchiveCryptHeader renamed 2018-04-29 10:13:46 +01:00
Adam Hathcock
15534f466a Add basic rar5 crypt header 2018-04-28 18:20:40 +01:00
Adam Hathcock
9d63dcb8d6 Uncommit some tests 2018-04-28 18:14:47 +01:00
Adam Hathcock
6efe30bd6e Merge branch 'master' into rar5
# Conflicts:
#	.gitignore
2018-04-28 18:09:10 +01:00
Adam Hathcock
52dd9f0609 Merge pull request #371 from adamhathcock/Issue-370
Expose stream length.  Clean up entry stream
2018-04-26 11:33:23 +01:00
Adam Hathcock
bee7f43880 Expose stream length. Clean up entry stream 2018-04-26 09:46:01 +01:00
Adam Hathcock
d38276e8cf Fix solid and some other tests 2018-04-23 10:29:46 +01:00
Adam Hathcock
f3daaeb200 Try to use both for Rarv5 support 2018-04-23 09:39:50 +01:00
Adam Hathcock
9b152a40a9 Merge branch 'master' into rar5 2018-04-22 11:35:33 +01:00
Adam Hathcock
89ae8ca526 Rejigger read only substream 2018-04-22 11:32:47 +01:00
Adam Hathcock
68a5e474a6 More testing of file handling 2018-04-22 11:19:11 +01:00
Adam Hathcock
bf58742ddf rework of leave stream open for readers 2018-04-22 11:09:03 +01:00
Adam Hathcock
f18e5b75bb Archives set up correctly 2018-04-22 10:06:30 +01:00
Adam Hathcock
e919c99b14 First pass of removing explicit leaveOpen on streams. 2018-04-22 10:02:18 +01:00
Adam Hathcock
b960f2e5ba Minor build updates 2018-04-22 09:17:03 +01:00
srperias@microsoft.com
5d8728d592 Decode without setting the default Encoding type 2018-03-28 13:12:54 -07:00
srperias@microsoft.com
04ba6c2d73 ZipArchive Reader: Uses IBM PC character encoding to decode filename and comment if the general purpose bit 11 is not set in the header 2018-03-27 13:54:16 -07:00
Adam Hathcock
0cab9bd4b4 Mark for 0.20.0 0.20.0 2018-03-24 07:42:20 +00:00
Adam Hathcock
279d305013 Merge pull request #359 from prettierci-commits/prettierci-master-1521104105
PrettierCI master Sync
2018-03-15 08:56:49 +00:00
PrettierCI
750c1fb069 Sync with Prettier 2018-03-15 08:55:06 +00:00
Adam Hathcock
359a6042cd Merge pull request #352 from adamhathcock/cake-026
Cake 0.26
2018-03-01 15:40:30 +00:00
Adam Hathcock
e27d2ec660 Remove netcoreapp1.x testing 2018-03-01 15:35:55 +00:00
Adam Hathcock
da56bfc01f Merge pull request #354 from frabar666/deflate64-decompress
Support Deflate64 decompression
2018-03-01 09:14:06 +00:00
frabar666
6e2c7d2857 support Deflate64 decompression 2018-02-27 23:31:11 +01:00
Adam Hathcock
5481609554 Build with new cake 2018-02-27 08:52:55 +00:00