From b3c1773b676e605955b0fe3d91bb862c189607c0 Mon Sep 17 00:00:00 2001 From: Looki2000 Date: Sun, 26 Feb 2023 11:20:01 +0100 Subject: [PATCH] fixed ''Zip Path Traversal Vulnerability'' --- .../net/minetest/minetest/UnzipService.java | 19 ++++++++++++++++--- 1 file changed, 16 insertions(+), 3 deletions(-) diff --git a/android/app/src/main/java/net/minetest/minetest/UnzipService.java b/android/app/src/main/java/net/minetest/minetest/UnzipService.java index a61a491..2199c28 100644 --- a/android/app/src/main/java/net/minetest/minetest/UnzipService.java +++ b/android/app/src/main/java/net/minetest/minetest/UnzipService.java @@ -156,7 +156,7 @@ public class UnzipService extends IntentService { int readLen; byte[] readBuffer = new byte[16384]; try (FileInputStream fileInputStream = new FileInputStream(zipFile); - ZipInputStream zipInputStream = new ZipInputStream(fileInputStream)) { + ZipInputStream zipInputStream = new ZipInputStream(fileInputStream)) { ZipEntry ze; while ((ze = zipInputStream.getNextEntry()) != null) { if (ze.isDirectory()) { @@ -165,8 +165,21 @@ public class UnzipService extends IntentService { continue; } publishProgress(notificationBuilder, R.string.loading, 100 * ++per / size); - try (OutputStream outputStream = new FileOutputStream( - new File(userDataDirectory, ze.getName()))) { + // Zip Path Traversal Vulnerability fix: https://support.google.com/faqs/answer/9294009 + + File new_file = new File(userDataDirectory, ze.getName()); + + String canonicalPath = new_file.getCanonicalPath(); + + // check if canonical path is inside the target directory + + //if (!canonicalPath.startsWith(userDataDirectory)) { + if (!canonicalPath.startsWith(String.valueOf(userDataDirectory))) { + throw new IOException("Unzipping failed due to security issue!"); + } + + //try (OutputStream outputStream = new FileOutputStream(new File(userDataDirectory, ze.getName()))) { + try (OutputStream outputStream = new FileOutputStream(new_file)) { while ((readLen = zipInputStream.read(readBuffer)) != -1) { outputStream.write(readBuffer, 0, readLen); }