Start a conversation

A zip-bomb can cause marc.search.exe to crash

Versions / Builds Affected

20131111, 20140616

Status

Resolved

Problem Summary

A zip-bomb can cause marc.search.exe to crash

TT / JIRAID

2222

How to Identify

A zip-bomb is an email with a zip-attachment which is rather small in size - maybe a few MB. The zip-attachment contains extremely large files (normally txt-files) which are compress extremely efficient with a high compression ratio; e.g. a few GB. http://en.wikipedia.org/wiki/Zip_bomb When marc.search.exe tries to index the zip-attachment, it extracts the large files but eventually fails to index the large file. ----- There are not specific logs which indicate this specific situation. The following high level steps should be taken to identify this issue: 1. The customer observes that marc.search.exe crashes (there should be generic crash Windows Application event logs) 2. When analyzing the debug logging, follow the Search logs to spot the last email which was indexed before the crash 3. The "next" email is potentially the zip-bomb 4. Download the "next" email from MARC and check if it is a zip-bomb

Workaround / Fix Details

Disable attachment indexing as a whole or only for zip/rar files. ----- Fixed in MARC2015 build 20141117

Required Actions

Upgrade to the version mentioned in the fix section
Choose files or drag and drop files
Was this article helpful?
Yes
No
  1. Priyanka Bhotika

  2. Posted

Comments