A zip-bomb can cause marc.search.exe to crash
Versions / Builds Affected
20131111, 20140616
Status
Resolved
Problem Summary
A zip-bomb can cause marc.search.exe to crash
TT / JIRAID
2222
How to Identify
A zip-bomb is an email with a zip-attachment which is rather small in size - maybe a few MB. The zip-attachment contains extremely large files (normally txt-files) which are compress extremely efficient with a high compression ratio; e.g. a few GB. http://en.wikipedia.org/wiki/Zip_bomb When marc.search.exe tries to index the zip-attachment, it extracts the large files but eventually fails to index the large file. ----- There are not specific logs which indicate this specific situation. The following high level steps should be taken to identify this issue: 1. The customer observes that marc.search.exe crashes (there should be generic crash Windows Application event logs) 2. When analyzing the debug logging, follow the Search logs to spot the last email which was indexed before the crash 3. The "next" email is potentially the zip-bomb 4. Download the "next" email from MARC and check if it is a zip-bomb
Workaround / Fix Details
Disable attachment indexing as a whole or only for zip/rar files. ----- Fixed in MARC2015 build 20141117
Required Actions
Upgrade to the version mentioned in the fix section
Priyanka Bhotika
Comments