Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Zip: Initial Project Proposal (google#12451)
I am requesting permission to integrate [zip](https://github.com/kuba--/zip) into OSSFuzz. I believe that this project is a good candidate for OSS-Fuzz integration as it serves as a preeminent file compression / decompression library used by many prominent projects (Windows [PowerToys](https://github.com/microsoft/PowerToys), The [Ring Programming Language](https://ring-lang.github.io/), and the [V Programming Language](https://github.com/vlang/v) to name a few). In addition to the possibility of uncovering edge-cases and bugs in the decompression of zip files, there is the possibility of a malicious actor crafting a corrupted zip file that could achieve DoS or, in an extreme case, privilege escalation and RCE. EDIT: Please see upstream approval for integration (and listing me as the primary contact) [here](https://github.com/kuba--/zip/issues/355)
- Loading branch information