[CVE-2021-3517] Validate UTF8 in xmlEncodeEntities 99/286699/1
authorJoel Hockey <joel.hockey@gmail.com>
Mon, 17 Aug 2020 00:19:35 +0000 (17:19 -0700)
committerDongHun Kwak <dh0128.kwak@samsung.com>
Thu, 12 Jan 2023 01:07:45 +0000 (10:07 +0900)
commitfce558e02dbb280cebfc492297ed63dfc9bdf922
tree374465fc3dc32d1b2d6234933c2f7ce1b4589587
parentfd644d554e894f3d3d33ba726511eab178535256
[CVE-2021-3517] Validate UTF8 in xmlEncodeEntities

Code is currently assuming UTF-8 without validating. Truncated UTF-8
input can cause out-of-bounds array access.

Adds further checks to partial fix in 50f06b3e.

Fixes #178

Change-Id: Ie12b322068d4550475a04fc5976a79e8a38231f9
Signed-off-by: DongHun Kwak <dh0128.kwak@samsung.com>
entities.c