From 90782df59146bc4d8f16a24593bde986aa424831 Mon Sep 17 00:00:00 2001 From: tanjiro Kamado Date: Sat, 26 Sep 2026 16:56:42 +0530 Subject: [PATCH] check gmtime_r return in httpGetDateString --- CHANGES.md | 2 ++ cups/http-support.c | 6 +++++- 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/CHANGES.md b/CHANGES.md index e36bc460c..39b2b8a14 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -18,6 +18,8 @@ v3.0.4 - YYYY-MM-DD by an unknown CA. - Fixed PAM support in `ippeveprinter`. - Updated dateTime parsing in IPP files. +- Fixed use of an uninitialized `struct tm` in `httpGetDateString` when + `gmtime_r` fails for an out-of-range time value. v3.0.3 - 2026-08-20 diff --git a/cups/http-support.c b/cups/http-support.c index 604187bc5..c55570696 100644 --- a/cups/http-support.c +++ b/cups/http-support.c @@ -636,7 +636,11 @@ httpGetDateString(time_t t, // I - Time in seconds struct tm tdate; // UNIX date/time data - gmtime_r(&t, &tdate); + if (!gmtime_r(&t, &tdate)) + { + memset(&tdate, 0, sizeof(tdate)); + tdate.tm_mday = 1; + } snprintf(s, slen, "%s, %02d %s %d %02d:%02d:%02d GMT", http_days[tdate.tm_wday], tdate.tm_mday, http_months[tdate.tm_mon], tdate.tm_year + 1900, tdate.tm_hour, tdate.tm_min, tdate.tm_sec);