Skip to content

check gmtime_r return in httpGetDateString - #167

Closed
tanjiroK-coder wants to merge 1 commit into
OpenPrinting:masterfrom
tanjiroK-coder:http-datestring-gmtime-null
Closed

tanjiroK-coder wants to merge 1 commit into
OpenPrinting:masterfrom
tanjiroK-coder:http-datestring-gmtime-null

Conversation

@tanjiroK-coder

Copy link
Copy Markdown
Contributor

httpGetDateString takes a time_t straight from the caller and feeds it to gmtime_r without checking the result. When the value falls outside the range gmtime_r can represent it returns NULL and leaves tdate untouched, and the code then uses tdate.tm_wday and tdate.tm_mon as indices into the 7- and 12-element http_days/http_months tables and hands the loaded pointer to %s, so an uninitialised tm_mon becomes an out-of-bounds read and a wild pointer dereference. The reachable path is cups-oauth, which passes (time_t)cupsJSONGetNumber(value) from a JWT exp/iat/nbf claim, so an id_token carrying exp: 9e18 is enough. I hit it reading the code after bb7b1e5 and confirmed gmtime_r returns NULL there; a build against the sanitiser faults with a SEGV inside httpGetDateString on that input. This is the same fix bb7b1e5 applied to the sibling ippTimeToDate, so I mirrored it here: zero the struct and set tm_mday to 1 when gmtime_r fails.

Assisted-by: Claude Code:Opus-4.8 [Claude Code]

@michaelrsweet

Copy link
Copy Markdown
Member

Thanks!

[master 6b47442] Fix httpGetDateString with bad date/time values (Issue #167)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants