Skip to content

Integer overflow in show_supplies() #1715

Description

@PavlNekrasov

show_supplies() inreads the supply level from the "supply%d" field of an unauthenticated GET request with atoi() and never range checks it.

level = atoi(val); // New level

The value is stored in printer-supply, read back with atoi()

level = atoi(supply_ptr + 6);

and used as "level * 2", which overflows for both large negative and large positive levels.

cups/tools/ippeveprinter.c

Lines 7649 to 7652 in e72b702

if (level < 10)
html_printf(client, "<td class=\"meter\"><span class=\"bar\" style=\"background: %s; padding: 5px %dpx;\"></span>&nbsp;%d%%</td></tr>\n", backgrounds[i], level * 2, level);
else
html_printf(client, "<td class=\"meter\"><span class=\"bar\" style=\"background: %s; color: %s; padding: 5px %dpx;\">%d%%</span></td></tr>\n", backgrounds[i], colors[i], level * 2, level);

Found by Linux Verification Center (portal.linuxtesting.ru) with SVACE.
Reporter: Pavel Nekrasov (p.nekrasov@fobos-nt.ru).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions