You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@pdfbox.apache.org by ti...@apache.org on 2018/03/05 17:18:17 UTC
svn commit: r1825917 -
/pdfbox/trunk/fontbox/src/main/java/org/apache/fontbox/ttf/GlyfSimpleDescript.java
Author: tilman
Date: Mon Mar 5 17:18:17 2018
New Revision: 1825917
URL: http://svn.apache.org/viewvc?rev=1825917&view=rev
Log:
PDFBOX-4140: avoid IOOB when repeating flag is outside of range, as suggested by Daniel Persson
Modified:
pdfbox/trunk/fontbox/src/main/java/org/apache/fontbox/ttf/GlyfSimpleDescript.java
Modified: pdfbox/trunk/fontbox/src/main/java/org/apache/fontbox/ttf/GlyfSimpleDescript.java
URL: http://svn.apache.org/viewvc/pdfbox/trunk/fontbox/src/main/java/org/apache/fontbox/ttf/GlyfSimpleDescript.java?rev=1825917&r1=1825916&r2=1825917&view=diff
==============================================================================
--- pdfbox/trunk/fontbox/src/main/java/org/apache/fontbox/ttf/GlyfSimpleDescript.java (original)
+++ pdfbox/trunk/fontbox/src/main/java/org/apache/fontbox/ttf/GlyfSimpleDescript.java Mon Mar 5 17:18:17 2018
@@ -205,7 +205,7 @@ public class GlyfSimpleDescript extends
if ((flags[index] & REPEAT) != 0)
{
int repeats = bais.readUnsignedByte();
- for (int i = 1; i <= repeats; i++)
+ for (int i = 1; i <= repeats && index + i < flags.length; i++)
{
flags[index + i] = flags[index];
}