Skip to content

tinker补丁zip解压缩漏洞 #1102

@szzwk

Description

@szzwk

使用安全扫描工具发现tinker源码的DexDiffPatchInternal.java的patchDexFile方法解压缩补丁时会有zip漏洞,如果压缩包里面的文件路径含有../字符,解压缩后文件可能会覆盖上层文件夹下面的同名文件,请问tinker何时修复这个漏洞呢。

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions