show_supplies() inreads the supply level from the "supply%d" field of an unauthenticated GET request with atoi() and never range checks it.
|
level = atoi(val); // New level |
The value is stored in printer-supply, read back with atoi()
|
level = atoi(supply_ptr + 6); |
and used as "level * 2", which overflows for both large negative and large positive levels.
|
if (level < 10) |
|
html_printf(client, "<td class=\"meter\"><span class=\"bar\" style=\"background: %s; padding: 5px %dpx;\"></span> %d%%</td></tr>\n", backgrounds[i], level * 2, level); |
|
else |
|
html_printf(client, "<td class=\"meter\"><span class=\"bar\" style=\"background: %s; color: %s; padding: 5px %dpx;\">%d%%</span></td></tr>\n", backgrounds[i], colors[i], level * 2, level); |
Found by Linux Verification Center (portal.linuxtesting.ru) with SVACE.
Reporter: Pavel Nekrasov (p.nekrasov@fobos-nt.ru).
show_supplies() inreads the supply level from the "supply%d" field of an unauthenticated GET request with atoi() and never range checks it.
cups/tools/ippeveprinter.c
Line 7598 in e72b702
The value is stored in printer-supply, read back with atoi()
cups/tools/ippeveprinter.c
Line 7640 in e72b702
and used as "level * 2", which overflows for both large negative and large positive levels.
cups/tools/ippeveprinter.c
Lines 7649 to 7652 in e72b702
Found by Linux Verification Center (portal.linuxtesting.ru) with SVACE.
Reporter: Pavel Nekrasov (p.nekrasov@fobos-nt.ru).