Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1231966 > unrolled thread

Bug#1095269: unar can't extract zip files with password

Started byZenWalker <scow@riseup.net>
First post2025-02-06 09:30 +0100
Last post2025-02-07 17:10 +0100
Articles 6 — 2 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1095269: unar can't extract zip files with password ZenWalker <scow@riseup.net> - 2025-02-06 09:30 +0100
    Bug#1095269: unar can't extract zip files with password Yavor Doganov <yavor@gnu.org> - 2025-02-06 14:20 +0100
    Bug#1095269: more details ZenWalker <scow@riseup.net> - 2025-02-06 15:40 +0100
      Bug#1095269: more details Yavor Doganov <yavor@gnu.org> - 2025-02-07 14:10 +0100
    Bug#1095269: more info ZenWalker <scow@riseup.net> - 2025-02-07 16:50 +0100
      Bug#1095269: more info Yavor Doganov <yavor@gnu.org> - 2025-02-07 17:10 +0100

#1231966 — Bug#1095269: unar can't extract zip files with password

FromZenWalker <scow@riseup.net>
Date2025-02-06 09:30 +0100
SubjectBug#1095269: unar can't extract zip files with password
Message-ID<Kd5qN-eMwX-7@gated-at.bofh.it>
Package: unar
Version: 1.10.8+ds1-7
Severity: normal

unar works with rar files with password, but it doesnt work with zip files with
password


-- System Information:
Debian Release: trixie/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.12.9-amd64 (SMP w/2 CPU threads; PREEMPT)
Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages unar depends on:
ii  gnustep-base-runtime  1.30.0-8
ii  libbz2-1.0            1.0.8-6
ii  libc6                 2.40-5
ii  libgcc-s1             14.2.0-12
ii  libgnustep-base1.30   1.30.0-8
ii  libicu72              72.1-6
ii  libobjc4              14.2.0-12
ii  libstdc++6            14.2.0-12
ii  libwavpack1           5.7.0-1+b1
ii  zlib1g                1:1.3.dfsg+really1.3.1-1+b1

unar recommends no packages.

unar suggests no packages.

-- no debconf information

[toc] | [next] | [standalone]


#1231991

FromYavor Doganov <yavor@gnu.org>
Date2025-02-06 14:20 +0100
Message-ID<Kd9Xr-ePIf-1@gated-at.bofh.it>
In reply to#1231966
Control: tags -1 + unreproducible moreinfo

ZenWalker wrote:
> Package: unar
> Version: 1.10.8+ds1-7

Thanks for the report but there's some discrepancy here: this version
is not in testing but reportbug says you're using testing.  Did you
install the package manually?

> unar works with rar files with password, but it doesnt work with zip
> files with password

I'm afraid I cannot reproduce:

$ echo bar > bar
$ echo baz > baz
$ zip -e foo bar baz
Enter password: 
Verify password: 
  adding: bar (stored 0%)
  adding: baz (stored 0%)
$ mkdir test && cd test
$ unar ../foo.zip 
../foo.zip: Zip
  bar  (4 B)... This archive requires a password to unpack.
Password (will not be shown): 
OK.
  baz  (4 B)... OK.
Successfully extracted to "foo".
$ cat foo/bar foo/baz
bar
baz

That's on unstable/amd64 with unar/1.10.8+ds1-7.

[toc] | [prev] | [next] | [standalone]


#1232000 — Bug#1095269: more details

FromZenWalker <scow@riseup.net>
Date2025-02-06 15:40 +0100
SubjectBug#1095269: more details
Message-ID<KdbcR-eQHj-7@gated-at.bofh.it>
In reply to#1231966
Hi, thanks for your quick reply!

I am in testing, and I installed the sid version to confirm if the bug
is there too.

I follow your steps and I confirm it works as expected.

You can see here the reproducible steps (using the password 1234):

$ echo bar > bar
$ echo baz > baz
$ 7z a -mem=AES128 -tzip -p1234 foo.zip bar baz

7-Zip 24.09 (x64) : Copyright (c) 1999-2024 Igor Pavlov : 2024-11-29
 64-bit locale=C.UTF-8 Threads:4 OPEN_MAX:1024

Scanning the drive:
2 files, 8 bytes (1 KiB)

Creating archive: foo.zip

Add new data to archive: 2 files, 8 bytes (1 KiB)

    
Files read from disk: 2
Archive size: 350 bytes (1 KiB)
Everything is Ok

$ mkdir test && cd test
$ unar ../foo.zip

../foo.zip: Zip
  bar  (4 B)... This archive requires a password to unpack.
Password (will not be shown): 
Failed! (Missing or wrong password)
  baz  (4 B)... Failed! (Missing or wrong password)
Extraction to directory "foo" failed (2 files failed.)

as you can see, the problem is with .zip files created with 7z and
-mem=AES128

[toc] | [prev] | [next] | [standalone]


#1232138 — Bug#1095269: more details

FromYavor Doganov <yavor@gnu.org>
Date2025-02-07 14:10 +0100
SubjectBug#1095269: more details
Message-ID<Kdwhj-f5j2-1@gated-at.bofh.it>
In reply to#1232000
Control: retitle -1 unar can't extract encrypted zip files created with 7z -mem=AES128
Control: tags -1 = confirmed
Control: severity -1 minor

ZenWalker wrote:
> I am in testing, and I installed the sid version to confirm if the
> bug is there too.

I see, but there's no reason to do that as it just causes confusion.
If you encounter a bug in a supported suite just file it.  The only
thing that's good to do is check if it isn't already reported.  It's
the maintainer's job to figure out if it is fixed or not in the higher
version.

> $ 7z a -mem=AES128 -tzip -p1234 foo.zip bar baz

This option (-mem) is undocumented and I can't say what it is doing.
unar successfully extracts an encrypted archive without it (it seems
7z is using AES-256 by default which is stronger) so I'm lowering the
severity.

BTW, unzip also cannot handle it:

$ unzip ../foo.zip 
Archive:  ../foo.zip
   skipping: bar                     need PK compat. v5.1 (can do v4.6)
   skipping: baz                     need PK compat. v5.1 (can do v4.6)

I don't have a clue what PK means.

[toc] | [prev] | [next] | [standalone]


#1232162 — Bug#1095269: more info

FromZenWalker <scow@riseup.net>
Date2025-02-07 16:50 +0100
SubjectBug#1095269: more info
Message-ID<KdyMa-f6Ig-11@gated-at.bofh.it>
In reply to#1231966
7z documentation:

https://documentation.help/7-Zip/method.htm

seems the default is ZipCrypto

unar works if the file is compressed with:

$ 7z a -mem=ZipCrypto -tzip -p1234 foo.zip bar baz
$ 7z a -tzip -p1234 foo.zip bar baz

and unar fails if the file is compressed with:

$ 7z a -mem=AES128 -tzip -p1234 foo.zip bar baz
$ 7z a -mem=AES192 -tzip -p1234 foo.zip bar baz
$ 7z a -mem=AES256 -tzip -p1234 foo.zip bar baz

[toc] | [prev] | [next] | [standalone]


#1232164 — Bug#1095269: more info

FromYavor Doganov <yavor@gnu.org>
Date2025-02-07 17:10 +0100
SubjectBug#1095269: more info
Message-ID<Kdz5v-f74n-3@gated-at.bofh.it>
In reply to#1232162
ZenWalker wrote:
> 7z documentation:
> 
> https://documentation.help/7-Zip/method.htm

Thanks; that's not available in the Debian package, I think.  It's
also impossible for me to read or understand.  There's no mem option
AFAICS with listed allowed parameters.  But nevermind.

> seems the default is ZipCrypto

So the AES-256 fanfares at their website are slightly misleading.

> unar works if the file is compressed with:
> 
> $ 7z a -mem=ZipCrypto -tzip -p1234 foo.zip bar baz
> $ 7z a -tzip -p1234 foo.zip bar baz

Yes, I tried the second invocation.

> and unar fails if the file is compressed with:
> 
> $ 7z a -mem=AES128 -tzip -p1234 foo.zip bar baz
> $ 7z a -mem=AES192 -tzip -p1234 foo.zip bar baz
> $ 7z a -mem=AES256 -tzip -p1234 foo.zip bar baz

OK, thanks for the info.  I'll look into this when I find some time.
Would appreciate if you report it upstream as well.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web