4 ms·
Author here :) > a belief by the author of this post that Info-ZIP is the canonical implementation ↑ Where did you get this from? I don't think nowadays ther
by gynvael 1y ago
Author here :)
> a belief by the author of this post that Info-ZIP is the canonical implementation
↑ Where did you get this from?
I don't think nowadays there's such a thing as a canonical implementation — ZIP implementation world is too fragmented and implementations are too widespread.
One more note is that the article isn't about who's right or wrong in terms of interpreting APPNOTE.TXT — this is besides the point. The point there is that a parser discrepancy can cause security issues, and the article documents just another discrepancy found in the real world implementations (and there are A LOT of these with regards to the ZIP format).
- cxr 1y ago> this makes sense—technically both the offset of the Central Directory and the size of the Central Directory are redundant when you consider that the End of Central Directory Record should be, well, at the end of the Central Directory. In a proper ZIP file the following equation should be true: (position_of_EoCDR - size_of_CD == offset_of_CD) This is a pretty clear statement on normativity. You also left out an important part of my comment when you quoted it. (The operative word at the front of the sentence is "seems".)
- gynvael 1y ago> This is a pretty clear statement on normativity. I disagree – it's a technical remark on redundancy of fields (this is related to my hypothesis in the article that redundancy in formats is the primary cause of parser discrepancy). It doesn't acknowledge InfoZIP being canonical in any way. > You also left out an important part of my comment when you quoted it. (The operative word at the front of the sentence is "seems".) Fair, though my point still stands.