pjfanning opened a new pull request, #1347:
URL: https://github.com/apache/poi/pull/1347

   `CryptoAPIDecryptor.getSummaryEntries` reads the stream descriptor count as 
an unsigned 32-bit field and uses it directly as an array length, with **no 
bound at all**:
   
   ```java
   int encryptedStreamDescriptorCount = Math.toIntExact(leis.readUInt());
   StreamDescriptorEntry[] entries = new 
StreamDescriptorEntry[encryptedStreamDescriptorCount];
   ```
   
   A crafted encrypted stream can therefore ask for a billion-element 
`StreamDescriptorEntry[]` from a handful of input bytes, before any entry data 
is read.
   
   ### Approach
   
   Rather than cap the count — any cap would be a guess, and could reject a 
valid document — the entries are now collected as they are parsed:
   
   ```java
   final long encryptedStreamDescriptorCount = leis.readUInt();
   List<StreamDescriptorEntry> entries = new ArrayList<>();
   for (long i = 0; i < encryptedStreamDescriptorCount; i++) { ... }
   ```
   
   Memory used is now proportional to the data actually present. A count larger 
than the stream can back hits end-of-file — `LittleEndianInputStream.checkEOF` 
throws on a short read — which the method's existing `catch` already turns into 
`IOException("summary entries can't be read")`. **No limit is imposed on well 
formed input**, so a document with an unusually large number of streams still 
parses as before.
   
   `entries` was only consumed by an enhanced-for loop, so a `List` drops in 
for the array.
   
   ### Context
   
   Found while sweeping `Math.toIntExact` call sites after #1345. It was the 
only genuinely unbounded allocation the sweep turned up; the separate 
`HwmfBitmapDib` cleanup is #1346.
   
   ### Tests
   
   `:poi:test --tests 'org.apache.poi.poifs.crypt.*'` passes (23 tests). 
Leaving the rest to CI.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to