Show HN: A better zip decoder
github.com
github.com
That said, some software works on the basis that if you can't imagine the exploit then there's no point making a fuss, following Postel's "be liberal in what you accept".
But it's better practice to be strict with invalid data and let someone else imagine the exploit for other parsers that are less strict. At worst, you surface implementation bugs quicker and fail fast. At best, you stay safe. Malware authors are more imaginative than library authors. Implementing the spec is hard enough. Tolerating deviations from the spec only opens up gaps and creates ambiguity, fertile soil for exploits.