mirror of
https://github.com/wxWidgets/wxWidgets.git
synced 2026-08-17 17:02:51 +08:00
wxZipEntry::LoadExtraInfo() calls wxZipHeader::Read64() up to three times on a wxZipHeader of length min(fieldLen, 28). Read64() doesn't bounds-check m_pos against m_size, so a short ZIP64 extra field returns uninitialised bytes from the header's 64-byte stack-allocated m_data and they end up in the entry's m_Size / m_CompressedSize / m_Offset. Reject the entry when fieldLen is below the requested 64-bit total. Closes #26507.
Tests
This directory contains tests for the library and is mostly useful for the
library developers. See the samples subdirectory for the examples that are
more useful to the application developers using the library.
If you do work on the library itself and would like to modify an existing or
add a new test, please see docs/contributing/how-to-write-unit-tests.md for
more information.
This file also contains the instructions for running the tests if you'd just like to do it to confirm that the library works correctly.