nuovo / spreadsheet-reader

A PHP spreadsheet reader (Excel XLS and XLSX, OpenOffice ODS, and variously separated text files) with a singular goal of getting the data out, efficiently
http://www.nuovo.lv/
Other
674 stars 498 forks source link

Zip Bomb attacks prevention issue #174

Closed mohamadsheam closed 2 years ago

mohamadsheam commented 2 years ago

Zip Bomb attacks Issue

Hi, Recently one of my applications was reviewed by a security review team. In my application, I have used this spreadsheet-reader library. In review, the team mentioned Zip Bomb attacks. If you look at the screenshot, you may understand.

Screenshot_4

So how can I prevent possible zip bomb attacks here? Let me know if any information needs to be clear. Thanks