Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-6267

Cannot unzip war archive due to "possible zip bomb"

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Won't Do
    • Icon: Major Major
    • None
    • rhel-8.5.0
    • unzip
    • None
    • Moderate
    • rhel-plumbers
    • ssg_core_services
    • 1
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • If docs needed, set a value
    • None
    • 57,005

      Description of problem:

      A customer using latest unzip on RHEL8 (unzip-6.0-45.el8_4.x86_64) cannot extract his war archive due to getting:
      """
      error: invalid zip file with overlapped components (possible zip bomb)
      """

      I don't manage to unzip the file myself on my Fedora 35 system (unzip-6.0-53.fc35.x86_64) nor latest on RHEL7 (only unzip-6.0-20.el7.x86_64 works).

      Version-Release number of selected component (if applicable):

      unzip-6.0-45.el8_4

      How reproducible:

      Always

              jamartis@redhat.com Jakub Martisko
              rhn-support-rmetrich Renaud Métrich
              Jakub Martisko Jakub Martisko
              RHEL CS Plumbers QE Bot RHEL CS Plumbers QE Bot
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: