mirror of
https://github.com/OrcaSlicer/OrcaSlicer.git
synced 2026-10-04 14:20:58 +00:00
Validate Zip Entry Sizes Before Parsing 3MF XML (#15958)
The 3MF importers read XML entries into a single expat buffer whose size is an int, while the archive extraction used the entry's 64-bit declared size. The two could disagree for entries declaring more than INT_MAX bytes. Reject such entries before allocating, and use one size for the buffer, the extraction and the parse. This applies to the BBS importer, the PrusaSlicer importer and the PrusaSlicer fingerprint probe. The load now fails with an error instead.
This commit is contained in:
@@ -311,14 +311,17 @@ bool PrusaFileParser::check_3mf_from_prusa(const std::string filename)
|
||||
|
||||
mz_zip_archive_file_stat stat;
|
||||
if (!mz_zip_reader_file_stat(&archive, model_file_index, &stat)) goto EXIT;
|
||||
// expat sizes its buffer with an int, so a larger entry cannot be parsed in one piece.
|
||||
if (stat.m_uncomp_size > static_cast<mz_uint64>(std::numeric_limits<int>::max())) goto EXIT;
|
||||
|
||||
void *parser_buffer = XML_GetBuffer(m_parser, (int) stat.m_uncomp_size);
|
||||
const int xml_size = static_cast<int>(stat.m_uncomp_size);
|
||||
void *parser_buffer = XML_GetBuffer(m_parser, xml_size);
|
||||
if (parser_buffer == nullptr) goto EXIT;
|
||||
|
||||
mz_bool res = mz_zip_reader_extract_file_to_mem(&archive, stat.m_filename, parser_buffer, (size_t) stat.m_uncomp_size, 0);
|
||||
mz_bool res = mz_zip_reader_extract_file_to_mem(&archive, stat.m_filename, parser_buffer, static_cast<size_t>(xml_size), 0);
|
||||
if (res == 0) goto EXIT;
|
||||
|
||||
XML_ParseBuffer(m_parser, (int) stat.m_uncomp_size, 1);
|
||||
XML_ParseBuffer(m_parser, xml_size, 1);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1357,19 +1360,26 @@ ModelVolumeType type_from_string(const std::string &s)
|
||||
XML_SetUserData(m_xml_parser, (void*)this);
|
||||
XML_SetElementHandler(m_xml_parser, _3MF_Importer::_handle_start_config_xml_element, _3MF_Importer::_handle_end_config_xml_element);
|
||||
|
||||
void* parser_buffer = XML_GetBuffer(m_xml_parser, (int)stat.m_uncomp_size);
|
||||
// expat sizes its buffer with an int, so a larger entry cannot be parsed in one piece.
|
||||
if (stat.m_uncomp_size > static_cast<mz_uint64>(std::numeric_limits<int>::max())) {
|
||||
add_error("Found invalid size");
|
||||
return false;
|
||||
}
|
||||
const int xml_size = static_cast<int>(stat.m_uncomp_size);
|
||||
|
||||
void* parser_buffer = XML_GetBuffer(m_xml_parser, xml_size);
|
||||
if (parser_buffer == nullptr) {
|
||||
add_error("Unable to create buffer");
|
||||
return false;
|
||||
}
|
||||
|
||||
mz_bool res = mz_zip_reader_extract_file_to_mem(&archive, stat.m_filename, parser_buffer, (size_t)stat.m_uncomp_size, 0);
|
||||
mz_bool res = mz_zip_reader_extract_file_to_mem(&archive, stat.m_filename, parser_buffer, static_cast<size_t>(xml_size), 0);
|
||||
if (res == 0) {
|
||||
add_error("Error while reading config data to buffer");
|
||||
return false;
|
||||
}
|
||||
|
||||
if (!XML_ParseBuffer(m_xml_parser, (int)stat.m_uncomp_size, 1)) {
|
||||
if (!XML_ParseBuffer(m_xml_parser, xml_size, 1)) {
|
||||
char error_buf[1024];
|
||||
::sprintf(error_buf, "Error (%s) while parsing xml file at line %d", XML_ErrorString(XML_GetErrorCode(m_xml_parser)), (int)XML_GetCurrentLineNumber(m_xml_parser));
|
||||
add_error(error_buf);
|
||||
|
||||
@@ -2512,19 +2512,26 @@ void PlateData::parse_filament_info(GCodeProcessorResult *result)
|
||||
XML_SetEntityDeclHandler(m_xml_parser, nullptr);
|
||||
XML_SetExternalEntityRefHandler(m_xml_parser, nullptr);
|
||||
|
||||
void* parser_buffer = XML_GetBuffer(m_xml_parser, (int)stat.m_uncomp_size);
|
||||
// expat sizes its buffer with an int, so a larger entry cannot be parsed in one piece.
|
||||
if (stat.m_uncomp_size > static_cast<mz_uint64>(std::numeric_limits<int>::max())) {
|
||||
add_error("Found invalid size");
|
||||
return false;
|
||||
}
|
||||
const int xml_size = static_cast<int>(stat.m_uncomp_size);
|
||||
|
||||
void* parser_buffer = XML_GetBuffer(m_xml_parser, xml_size);
|
||||
if (parser_buffer == nullptr) {
|
||||
add_error("Unable to create buffer");
|
||||
return false;
|
||||
}
|
||||
|
||||
mz_bool res = mz_zip_reader_extract_file_to_mem(&archive, stat.m_filename, parser_buffer, (size_t)stat.m_uncomp_size, 0);
|
||||
mz_bool res = mz_zip_reader_extract_file_to_mem(&archive, stat.m_filename, parser_buffer, static_cast<size_t>(xml_size), 0);
|
||||
if (res == 0) {
|
||||
add_error("Error while reading config data to buffer");
|
||||
return false;
|
||||
}
|
||||
|
||||
if (!XML_ParseBuffer(m_xml_parser, (int)stat.m_uncomp_size, 1)) {
|
||||
if (!XML_ParseBuffer(m_xml_parser, xml_size, 1)) {
|
||||
char error_buf[1024];
|
||||
::snprintf(error_buf, 1024, "Error (%s) while parsing xml file at line %d", XML_ErrorString(XML_GetErrorCode(m_xml_parser)), (int)XML_GetCurrentLineNumber(m_xml_parser));
|
||||
add_error(error_buf);
|
||||
|
||||
Reference in New Issue
Block a user