Blame SOURCES/icu.10318.CVE-2013-2924_changeset_34076.patch

f9b135
Index: /icu/trunk/source/i18n/csrucode.cpp
f9b135
===================================================================
f9b135
--- orig.icu/source/i18n/csrucode.cpp	(revision 34075)
f9b135
+++ icu/source/i18n/csrucode.cpp	(revision 34076)
f9b135
@@ -1,5 +1,5 @@
f9b135
 /*
f9b135
  **********************************************************************
f9b135
- *   Copyright (C) 2005-2012, International Business Machines
f9b135
+ *   Copyright (C) 2005-2013, International Business Machines
f9b135
  *   Corporation and others.  All Rights Reserved.
f9b135
  **********************************************************************
f9b135
@@ -34,6 +34,7 @@
f9b135
     const uint8_t *input = textIn->fRawInput;
f9b135
     int32_t confidence = 0;
f9b135
+    int32_t length = textIn->fRawLength;
f9b135
 
f9b135
-    if (input[0] == 0xFE && input[1] == 0xFF) {
f9b135
+    if (length >=2 && input[0] == 0xFE && input[1] == 0xFF) {
f9b135
         confidence = 100;
f9b135
     }
f9b135
@@ -58,6 +59,7 @@
f9b135
     const uint8_t *input = textIn->fRawInput;
f9b135
     int32_t confidence = 0;
f9b135
+    int32_t length = textIn->fRawLength;
f9b135
 
f9b135
-    if (input[0] == 0xFF && input[1] == 0xFE && (input[2] != 0x00 || input[3] != 0x00)) {
f9b135
+    if (length >= 4 && input[0] == 0xFF && input[1] == 0xFE && (input[2] != 0x00 || input[3] != 0x00)) {
f9b135
         confidence = 100;
f9b135
     }
f9b135
@@ -82,5 +84,5 @@
f9b135
     int32_t confidence = 0;
f9b135
 
f9b135
-    if (getChar(input, 0) == 0x0000FEFFUL) {
f9b135
+    if (limit > 0 && getChar(input, 0) == 0x0000FEFFUL) {
f9b135
         hasBOM = TRUE;
f9b135
     }