Uploaded image for project: 'Qt'
  1. Qt
  2. QTBUG-91870

QDecompressHelper's archive bomb minimum limit should be adjustable

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: P2: Important P2: Important
    • 6.2.0 Alpha
    • 6.2
    • Network: HTTP
    • None
    • All
    • 5
    • 69982182a394618d4f121d2938d7d76196fe78f6 (qt/qtbase/dev)
    • Qt6_Foundation_Sprint 34

      Preferably on a per-request basis it should be possible to set the minimum size before the archive bomb checker kicks in. Currently it's 10MB, but for a 'trusted website' users may want to increase it if they know some files may have 'suspicious' decompression ratios. Or they know the systems their code will run on is guaranteed to have more RAM available than this so decompressing e.g. >100MB of an archive bomb would not be considered a problem.

        For Gerrit Dashboard: QTBUG-91870
        # Subject Branch Project Status CR V

            manordheim Mårten Nordheim
            manordheim Mårten Nordheim
            Vladimir Minenko Vladimir Minenko
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved:

                There are no open Gerrit changes