Commit f9a63e0c9473cc2b95fee27057a2a76e7233908b

Authored by Philippe Lagadec
Committed by GitHub
2 parents e9dca546 53813916

Merge pull request #396 from idiom/master

Update rtfobj to use the extension from the temp path of an embedded Package object
Showing 1 changed file with 10 additions and 3 deletions
oletools/rtfobj.py
... ... @@ -880,9 +880,16 @@ def process_file(container, filename, data, output_dir=None, save_object=False):
880 880 ole_column += '\nTemp path = %r' % rtfobj.temp_path
881 881 ole_color = 'yellow'
882 882 # check if the file extension is executable:
883   - _, ext = os.path.splitext(rtfobj.filename)
884   - log.debug('File extension: %r' % ext)
885   - if re_executable_extensions.match(ext):
  883 +
  884 + _, temp_ext = os.path.splitext(rtfobj.temp_path)
  885 + log.debug('Temp path extension: %r' % temp_ext)
  886 + _, file_ext = os.path.splitext(rtfobj.filename)
  887 + log.debug('File extension: %r' % file_ext)
  888 +
  889 + if temp_ext != file_ext:
  890 + ole_column += "\nMODIFIED FILE EXTENSION"
  891 +
  892 + if re_executable_extensions.match(temp_ext) or re_executable_extensions.match(file_ext):
886 893 ole_color = 'red'
887 894 ole_column += '\nEXECUTABLE FILE'
888 895 # else:
... ...