[Coco] Big Security Issue

edward jaquay ejjaquay at gmail.com
Sat May 27 20:59:17 EDT 2023


>
>
> It should be trivial to modify decompression programs to refuse to
decompress more than a few hundred times the compressed file size, which
should effectively defeat all zip file bombs.  Now that it has become an
issue it is hard to believe google, microsoft, and others will not do so if
they have not already done so.

In the meantime since I am already running pihole blocking .zip domains
will be easy for me.

>


More information about the Coco mailing list