Skip to content

Fix Integer overflow in httpGetDateTime() - #1717 - #1718

Open
PavlNekrasov wants to merge 1 commit into
OpenPrinting:masterfrom
PavlNekrasov:fix-integer-overflow-httpgetdatetime
Open

PavlNekrasov wants to merge 1 commit into
OpenPrinting:masterfrom
PavlNekrasov:fix-integer-overflow-httpgetdatetime

Conversation

@PavlNekrasov

Copy link
Copy Markdown

fixed #1717

Solution:
Range checked day, hour, min and sec and added the missing lower bound on year right after sscanf(), so every following expression stays inside int.

Signed-off-by: p.nekrasov@fobos-nt.ru
Signed-off-by: Timofei Fedotov sovtouch@altlinux.org

@michaelrsweet michaelrsweet self-assigned this Sep 24, 2026
@michaelrsweet michaelrsweet added the investigating Investigating the issue label Sep 24, 2026
@michaelrsweet

Copy link
Copy Markdown
Member

In the future, please combine bug report and PR into a single PR with the full explanation of the bug. Doing both just gives both of us extra work.

@michaelrsweet

Copy link
Copy Markdown
Member

Also, please start signing your commits...

Problem:
httpGetDateTime() never range checks day, hour, min, sec and the lower bound of year after sscanf(), so they overflow in the int arithmetic that follows. The date string is remote input - cupsd feeds it the If-Modified-Since request header.
Solution: Range checked day, hour, min, sec and year right after sscanf().
Signed-off-by: p.nekrasov@fobos-nt.ru
Signed-off-by: Timofei Fedotov sovtouch@altlinux.org
@PavlNekrasov
PavlNekrasov force-pushed the fix-integer-overflow-httpgetdatetime branch from 7e9c8b5 to da4902f Compare September 25, 2026 12:44
@PavlNekrasov

Copy link
Copy Markdown
Author

The commit has now been signed and forced-pushed.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

investigating Investigating the issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Integer overflow in httpGetDateTime()

2 participants