What are some possible reasons for "Zip Path Traversal Vulnerability" happens only in Android 11?

Viewed 1202

Based on https://support.google.com/faqs/answer/9294009, we implement "Zip Path Traversal Vulnerability" detection in our code.

We are getting crash log from Google Play Console, as we run throw new SecurityException("https://support.google.com/faqs/answer/9294009"); explicitly when we encounter "Zip Path Traversal Vulnerability".

Currently, sometimes, I have "Zip Path Traversal Vulnerability" happens only in Android 11.

public static boolean extractZipFile(InputStream inputStream, String destDirectory, boolean overwrite) {
    ZipInputStream zipInputStream = null;
    boolean status = true;

    try {
        zipInputStream = new ZipInputStream(inputStream);
        final byte[] data = new byte[1024];

        while (true) {
            ZipEntry zipEntry = null;
            FileOutputStream outputStream = null;

            try {
                zipEntry = zipInputStream.getNextEntry();

                if (zipEntry == null) {
                    break;
                }

                final File destination = new File(destDirectory, zipEntry.getName());
                final String canonicalPath = destination.getCanonicalPath();
                if (!canonicalPath.startsWith(destDirectory)) {
                    throw new SecurityException("https://support.google.com/faqs/answer/9294009");
                }

I always ensure destDirectory is non null, before calling extractZipFile

public static boolean extractZipFile(InputStream inputStream, boolean overwrite) {
    String destDirectory = Utils.getUserDataDirectory();
    if (destDirectory == null) {
        return false;
    }
    return extractZipFile(inputStream, destDirectory, overwrite);
}

public static String getUserDataDirectory() {
    if (externalFilesDir == null) {
        File _externalFilesDir = JStockApplication.instance().getExternalFilesDir(null);
        externalFilesDir = _externalFilesDir;
        if (externalFilesDir == null) {
            return null;
        }
    }
    
    return toEndWithFileSeperator(externalFilesDir.toString()) + getApplicationVersionString() + File.separator;
}

private static String toEndWithFileSeperator(String string) {
    if (string.endsWith(File.separator)) {
        return string;
    }
    return string + File.separator;
}

public static String getApplicationVersionString() {
    return "1.0.7";
}

Based on the posed source code, do you have any guess reason, why "Zip Path Traversal Vulnerability" happens only in Android 11? I use emulator Android 11 but not able to reproduce the problem.


Where does the zip file come from?

The zip file comes from 2 places

Bundled with APK as shown in below screenshot

enter image description here

We use the following code to extract it during runtime.

private void initPreloadDatabase(boolean overWrite) {
    AssetManager assetManager = getResources().getAssets();
    InputStream inputStream = null;
    try {
        inputStream = assetManager.open("database" + File.separator + "database.zip");
    } catch (IOException e) {
        Log.e(TAG, "", e);
    }
    if (inputStream != null) {
        org.yccheok.jstock.gui.Utils.extractZipFile(inputStream, overWrite);
    }
}

Another zip file is downloaded from

https://raw.githubusercontent.com/yccheok/jstock/master/appengine/jstock-android-static/war/stocks_information/unitedstate/stocks.zip

1 Answers

In Utils.getUserDataDirectory() function use:

getFilesDir().getCanonicalFile() 

instead of

getExternalFilesDir()
Related