c807425
From 7bb2a4671503c41d63989dcef9ef54dea0c73b43 Mon Sep 17 00:00:00 2001
c807425
From: Tatsuya Kinoshita <tats@debian.org>
c807425
Date: Thu, 7 Apr 2016 06:42:55 +0900
c807425
Subject: Fix segfault on bogus text
c807425
c807425
Bug-Debian: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=820162
c807425
---
c807425
 libwc/map/big5_ucs.map               |  4 ++-
c807425
 libwc/map/cns11643_ucs.map           |  8 +++--
c807425
 libwc/map/gb12345_ucs.map            |  4 ++-
c807425
 libwc/map/gb2312_ucs.map             |  4 ++-
c807425
 libwc/map/gbk_ucs.map                |  4 ++-
c807425
 libwc/map/hkscs_ucs.map              |  4 ++-
c807425
 libwc/map/jisx0208x0212x0213_ucs.map |  8 +++--
c807425
 libwc/map/ksx1001_ucs.map            |  4 ++-
c807425
 libwc/map/sjis_ext_ucs.map           |  4 ++-
c807425
 libwc/map/uhc_ucs.map                |  4 ++-
c807425
 libwc/ucs.c                          |  6 ++++
c807425
 libwc/ucs.map                        | 57 ++++++++++++++++++++++++++++++++++++
c807425
 12 files changed, 99 insertions(+), 12 deletions(-)
c807425
c807425
diff --git a/libwc/map/big5_ucs.map b/libwc/map/big5_ucs.map
c807425
index 0c6fd12..ac817a9 100644
c807425
--- a/libwc/map/big5_ucs.map
c807425
+++ b/libwc/map/big5_ucs.map
c807425
@@ -1,6 +1,8 @@
c807425
 /* Big5 (Chinese Taiwan) */
c807425
 
c807425
-static wc_uint16 big5_ucs_map[ 0x59 * 0x9D ] = {
c807425
+#define N_big5_ucs_map (0x59 * 0x9D)
c807425
+
c807425
+static wc_uint16 big5_ucs_map[ N_big5_ucs_map ] = {
c807425
  0x3000,	/* 0xA140 */
c807425
  0xFF0C,	/* 0xA141 */
c807425
  0x3001,	/* 0xA142 */
c807425
diff --git a/libwc/map/cns11643_ucs.map b/libwc/map/cns11643_ucs.map
c807425
index b426dd3..fcba334 100644
c807425
--- a/libwc/map/cns11643_ucs.map
c807425
+++ b/libwc/map/cns11643_ucs.map
c807425
@@ -1,6 +1,8 @@
c807425
 /* CNS 11643 (Chinese Taiwan) */
c807425
 
c807425
-static wc_uint16 cns116431_ucs_map[ 0x5E * 0x5E ] = {
c807425
+#define N_cns116431_ucs_map (0x5E * 0x5E)
c807425
+
c807425
+static wc_uint16 cns116431_ucs_map[ N_cns116431_ucs_map ] = {
c807425
  0x3000,	/* 0x2121 */
c807425
  0xFF0C,	/* 0x2122 */
c807425
  0x3001,	/* 0x2123 */
c807425
@@ -8839,7 +8841,9 @@ static wc_uint16 cns116431_ucs_map[ 0x5E * 0x5E ] = {
c807425
  0,		/* 0x7E7E */
c807425
 };
c807425
 
c807425
-static wc_uint16 cns116432_ucs_map[ 0x5E * 0x5E ] = {
c807425
+#define N_cns116432_ucs_map (0x5E * 0x5E)
c807425
+
c807425
+static wc_uint16 cns116432_ucs_map[ N_cns116432_ucs_map ] = {
c807425
  0x4E42,	/* 0x2121 */
c807425
  0x4E5C,	/* 0x2122 */
c807425
  0x51F5,	/* 0x2123 */
c807425
diff --git a/libwc/map/gb12345_ucs.map b/libwc/map/gb12345_ucs.map
c807425
index 55558c7..3fb338d 100644
c807425
--- a/libwc/map/gb12345_ucs.map
c807425
+++ b/libwc/map/gb12345_ucs.map
c807425
@@ -1,6 +1,8 @@
c807425
 /* GB 12345 (Chinese) */
c807425
 
c807425
-static wc_uint16 gb12345_ucs_map[ 0x5E * 0x5E ] = {
c807425
+#define N_gb12345_ucs_map (0x5E * 0x5E)
c807425
+
c807425
+static wc_uint16 gb12345_ucs_map[ N_gb12345_ucs_map ] = {
c807425
  0x3000,	/* 0x2121 */
c807425
  0x3001,	/* 0x2122 */
c807425
  0x3002,	/* 0x2123 */
c807425
diff --git a/libwc/map/gb2312_ucs.map b/libwc/map/gb2312_ucs.map
c807425
index 38fb88f..3d37465 100644
c807425
--- a/libwc/map/gb2312_ucs.map
c807425
+++ b/libwc/map/gb2312_ucs.map
c807425
@@ -1,6 +1,8 @@
c807425
 /* GB 2312 (Chinese) */
c807425
 
c807425
-static wc_uint16 gb2312_ucs_map[ 0x5E * 0x5E ] = {
c807425
+#define N_gb2312_ucs_map (0x5E * 0x5E)
c807425
+
c807425
+static wc_uint16 gb2312_ucs_map[ N_gb2312_ucs_map ] = {
c807425
  0x3000,	/* 0x2121 */
c807425
  0x3001,	/* 0x2122 */
c807425
  0x3002,	/* 0x2123 */
c807425
diff --git a/libwc/map/gbk_ucs.map b/libwc/map/gbk_ucs.map
c807425
index 5a0d5ba..d092fd7 100644
c807425
--- a/libwc/map/gbk_ucs.map
c807425
+++ b/libwc/map/gbk_ucs.map
c807425
@@ -6,7 +6,9 @@ static wc_map ucs_gbk_80_map[ N_ucs_gbk_80_map ] = {
c807425
   { 0x20AC, 0x0080 },
c807425
 };
c807425
 
c807425
-static wc_uint16 gbk_ucs_map[ 0x7E * 0xBE - 0x5E * 0x5E + 0x0A + 0x16 + 0x06 ] = {
c807425
+#define N_gbk_ucs_map (0x7E * 0xBE - 0x5E * 0x5E + 0x0A + 0x16 + 0x06)
c807425
+
c807425
+static wc_uint16 gbk_ucs_map[ N_gbk_ucs_map ] = {
c807425
   0x4E02,	/* 0x8140 */
c807425
   0x4E04,	/* 0x8141 */
c807425
   0x4E05,	/* 0x8142 */
c807425
diff --git a/libwc/map/hkscs_ucs.map b/libwc/map/hkscs_ucs.map
c807425
index 96d1566..2fbe6b4 100644
c807425
--- a/libwc/map/hkscs_ucs.map
c807425
+++ b/libwc/map/hkscs_ucs.map
c807425
@@ -1,6 +1,8 @@
c807425
 /* HKSCS (Chinese Hong Kong) */
c807425
 
c807425
-static wc_uint16 hkscs_ucs_map[ 0x1E * 0x9D ] = {
c807425
+#define N_hkscs_ucs_map (0x1E * 0x9D)
c807425
+
c807425
+static wc_uint16 hkscs_ucs_map[ N_hkscs_ucs_map ] = {
c807425
  0,		/* 0x8840 */
c807425
  0,		/* 0x8841 */
c807425
  0,		/* 0x8842 */
c807425
diff --git a/libwc/map/jisx0208x0212x0213_ucs.map b/libwc/map/jisx0208x0212x0213_ucs.map
c807425
index 1a1d706..28c2a6c 100644
c807425
--- a/libwc/map/jisx0208x0212x0213_ucs.map
c807425
+++ b/libwc/map/jisx0208x0212x0213_ucs.map
c807425
@@ -1,6 +1,8 @@
c807425
 /* JIS X 0208, JIS X 0212, JIS X 0213 (Japanese) */
c807425
 
c807425
-static wc_uint16 jisx0208x02131_ucs_map[ 0x5E * 0x5E ] = {
c807425
+#define N_jisx0208x02131_ucs_map (0x5E * 0x5E)
c807425
+
c807425
+static wc_uint16 jisx0208x02131_ucs_map[ N_jisx0208x02131_ucs_map ] = {
c807425
  0x3000,	/* JIS X 0208 0x2121 */
c807425
  0x3001,	/* JIS X 0208 0x2122 */
c807425
  0x3002,	/* JIS X 0208 0x2123 */
c807425
@@ -8839,7 +8841,9 @@ static wc_uint16 jisx0208x02131_ucs_map[ 0x5E * 0x5E ] = {
c807425
  0,		/* JIS X 0213-1 0x7E7E */
c807425
 };
c807425
 
c807425
-static wc_uint16 jisx0212x02132_ucs_map[ 0x5E * 0x5E ] = {
c807425
+#define N_jisx0212x02132_ucs_map (0x5E * 0x5E)
c807425
+
c807425
+static wc_uint16 jisx0212x02132_ucs_map[ N_jisx0212x02132_ucs_map ] = {
c807425
  0,		/* JIS X 0213-2 0x2121 */
c807425
  0x4E02,	/* JIS X 0213-2 0x2122 */
c807425
  0x4E0F,	/* JIS X 0213-2 0x2123 */
c807425
diff --git a/libwc/map/ksx1001_ucs.map b/libwc/map/ksx1001_ucs.map
c807425
index 9a17d61..cb62f98 100644
c807425
--- a/libwc/map/ksx1001_ucs.map
c807425
+++ b/libwc/map/ksx1001_ucs.map
c807425
@@ -1,6 +1,8 @@
c807425
 /* KS X 1001 (Korean) */
c807425
 
c807425
-static wc_uint16 ksx1001_ucs_map[ 0x5E * 0x5E ] = {
c807425
+#define N_ksx1001_ucs_map (0x5E * 0x5E)
c807425
+
c807425
+static wc_uint16 ksx1001_ucs_map[ N_ksx1001_ucs_map ] = {
c807425
  0x3000,	/* 0x2121 */
c807425
  0x3001,	/* 0x2122 */
c807425
  0x3002,	/* 0x2123 */
c807425
diff --git a/libwc/map/sjis_ext_ucs.map b/libwc/map/sjis_ext_ucs.map
c807425
index a82995c..cc748ba 100644
c807425
--- a/libwc/map/sjis_ext_ucs.map
c807425
+++ b/libwc/map/sjis_ext_ucs.map
c807425
@@ -1,6 +1,8 @@
c807425
 /* Shift_JIS/CP932 (Japanese) */
c807425
 
c807425
-static wc_uint16 sjis_ext_ucs_map[ 0x5E * 10 ] = {
c807425
+#define N_sjis_ext_ucs_map (0x5E * 10)
c807425
+
c807425
+static wc_uint16 sjis_ext_ucs_map[ N_sjis_ext_ucs_map ] = {
c807425
   0x2460,	/* 0x8740 */
c807425
   0x2461,	/* 0x8741 */
c807425
   0x2462,	/* 0x8742 */
c807425
diff --git a/libwc/map/uhc_ucs.map b/libwc/map/uhc_ucs.map
c807425
index b6b43ca..55efc09 100644
c807425
--- a/libwc/map/uhc_ucs.map
c807425
+++ b/libwc/map/uhc_ucs.map
c807425
@@ -1,6 +1,8 @@
c807425
 /* UHC/CP949 (Korean) */
c807425
 
c807425
-static wc_uint16 uhc_ucs_map[ 0x20 * 0xB2 + 0x27 * 0x54 + 2 ] = {
c807425
+#define N_uhc_ucs_map (0x20 * 0xB2 + 0x27 * 0x54 + 2)
c807425
+
c807425
+static wc_uint16 uhc_ucs_map[ N_uhc_ucs_map ] = {
c807425
   0xAC02,	/* 0x8141 */
c807425
   0xAC03,	/* 0x8142 */
c807425
   0xAC05,	/* 0x8143 */
c807425
diff --git a/libwc/ucs.c b/libwc/ucs.c
c807425
index 5e78b4e..727e574 100644
c807425
--- a/libwc/ucs.c
c807425
+++ b/libwc/ucs.c
c807425
@@ -109,6 +109,7 @@ wc_any_to_ucs(wc_wchar_t cc)
c807425
 {
c807425
     int f;
c807425
     wc_uint16 *map = NULL;
c807425
+    wc_uint32 map_size = 0x80;
c807425
     wc_map *map2;
c807425
 
c807425
     f = WC_CCS_INDEX(cc.ccs);
c807425
@@ -139,6 +140,7 @@ wc_any_to_ucs(wc_wchar_t cc)
c807425
 	if (f < WC_F_ISO_BASE || f > WC_F_CS94W_END)
c807425
 	    return 0;
c807425
 	map = cs94w_ucs_map[f - WC_F_ISO_BASE];
c807425
+	map_size = cs94w_ucs_map_size[f - WC_F_ISO_BASE];
c807425
 	cc.code = WC_CS94W_N(cc.code);
c807425
 	break;
c807425
     case WC_CCS_A_CS96:
c807425
@@ -151,6 +153,7 @@ wc_any_to_ucs(wc_wchar_t cc)
c807425
 	if (f < WC_F_ISO_BASE || f > WC_F_CS96W_END)
c807425
 	    return WC_C_UCS4_ERROR;
c807425
 	map = cs96w_ucs_map[f - WC_F_ISO_BASE];
c807425
+	map_size = cs96w_ucs_map_size[f - WC_F_ISO_BASE];
c807425
 	cc.code = WC_CS96W_N(cc.code);
c807425
 	break;
c807425
     case WC_CCS_A_CS942:
c807425
@@ -181,6 +184,7 @@ wc_any_to_ucs(wc_wchar_t cc)
c807425
 	if (f < WC_F_PCS_BASE || f > WC_F_PCSW_END)
c807425
 	    return WC_C_UCS4_ERROR;
c807425
 	map = pcsw_ucs_map[f - WC_F_PCS_BASE];
c807425
+	map_size = pcsw_ucs_map_size[f - WC_F_PCS_BASE];
c807425
 	switch (cc.ccs) {
c807425
 	case WC_CCS_BIG5:
c807425
 	    cc.code = WC_BIG5_N(cc.code);
c807425
@@ -272,6 +276,8 @@ wc_any_to_ucs(wc_wchar_t cc)
c807425
     }
c807425
     if (map == NULL)
c807425
 	return WC_C_UCS4_ERROR;
c807425
+    if (map_size == 0 || cc.code > map_size - 1)
c807425
+	return WC_C_UCS4_ERROR;
c807425
     cc.code = map[cc.code];
c807425
     return cc.code ? cc.code : WC_C_UCS4_ERROR;
c807425
 }
c807425
diff --git a/libwc/ucs.map b/libwc/ucs.map
c807425
index dfac6d9..5d6f688 100644
c807425
--- a/libwc/ucs.map
c807425
+++ b/libwc/ucs.map
c807425
@@ -195,7 +195,28 @@ static wc_uint16 *cs94w_ucs_map[] = {
c807425
   jisx0212x02132_ucs_map,	/* 50 (JIS X 0213-2) */
c807425
 };
c807425
 
c807425
+static wc_uint32 cs94w_ucs_map_size[] = {
c807425
+  N_jisx0208x02131_ucs_map,	/* 40 (JIS C 6226) */
c807425
+  N_gb2312_ucs_map,		/* 41 (GB 2312) */
c807425
+  N_jisx0208x02131_ucs_map,	/* 42 (JIS X 0208) */
c807425
+  N_ksx1001_ucs_map,		/* 43 (KS X 1001) */
c807425
+  N_jisx0212x02132_ucs_map,	/* 44 (JIS X 0212) */
c807425
+  0,				/* 45 (ISO IR 165) */
c807425
+  0,				/* 46 */
c807425
+  N_cns116431_ucs_map,		/* 47 (CNS 11643-1) */
c807425
+  N_cns116432_ucs_map,		/* 48 (CNS 11643-2) */
c807425
+  0,				/* 49 (CNS 11643-3) */
c807425
+  0,				/* 4A (CNS 11643-4) */
c807425
+  0,				/* 4B (CNS 11643-5) */
c807425
+  0,				/* 4C (CNS 11643-6) */
c807425
+  0,				/* 4D (CNS 11643-7) */
c807425
+  0,				/* 4E (KSP 9566) */
c807425
+  N_jisx0208x02131_ucs_map,	/* 4F (JIS X 0213-1) */
c807425
+  N_jisx0212x02132_ucs_map,	/* 50 (JIS X 0213-2) */
c807425
+};
c807425
+
c807425
 static wc_uint16 **cs96w_ucs_map;
c807425
+static wc_uint32 *cs96w_ucs_map_size;
c807425
 
c807425
 static wc_uint16 *pcsw_ucs_map[] = {
c807425
   big5_ucs_map,		/* Big5 */
c807425
@@ -233,6 +254,42 @@ static wc_uint16 *pcsw_ucs_map[] = {
c807425
   hkscs_ucs_map,	/* HKSCS-2 */
c807425
 };
c807425
 
c807425
+static wc_uint32 pcsw_ucs_map_size[] = {
c807425
+  N_big5_ucs_map,	/* Big5 */
c807425
+  N_big5_ucs_map,	/* Big5-1 */
c807425
+  N_big5_ucs_map,	/* Big5-2 */
c807425
+  0,			/* CNS 11643-8 */
c807425
+  0,			/* CNS 11643-9 */
c807425
+  0,			/* CNS 11643-10 */
c807425
+  0,			/* CNS 11643-11 */
c807425
+  0,			/* CNS 11643-12 */
c807425
+  0,			/* CNS 11643-13 */
c807425
+  0,			/* CNS 11643-14 */
c807425
+  0,			/* CNS 11643-15 */
c807425
+  0,			/* CNS 11643-16 */
c807425
+  0,			/* CNS 11643-X */
c807425
+  N_gb12345_ucs_map,	/* GB 12345 */
c807425
+  0,			/* Johab (special conversion) */
c807425
+  0,			/* Johab-1 (special conversion) */
c807425
+  0,			/* Johab-2 (special conversion) */
c807425
+  N_ksx1001_ucs_map,	/* Johab-3 */
c807425
+  N_sjis_ext_ucs_map,	/* Shift_JIS(CP932) ext */
c807425
+  N_sjis_ext_ucs_map,	/* Shift_JIS(CP932) ext-1 */
c807425
+  N_sjis_ext_ucs_map,	/* Shift_JIS(CP932) ext-2 */
c807425
+  N_gbk_ucs_map,	/* GBK(CP936) */
c807425
+  N_gbk_ucs_map,	/* GBK(CP936)-1 */
c807425
+  N_gbk_ucs_map,	/* GBK(CP936)-2 */
c807425
+  0,			/* GB18030 GBK-ext (special conversion) */
c807425
+  0,			/* GB18030 GBK-ext-1 (special conversion) */
c807425
+  0,			/* GB18030 GBK-ext-2 (special conversion) */
c807425
+  N_uhc_ucs_map,	/* UHC(CP949) */
c807425
+  N_uhc_ucs_map,	/* UHC(CP949)-1 */
c807425
+  N_uhc_ucs_map,	/* UHC(CP949)-2 */
c807425
+  N_hkscs_ucs_map,	/* HKSCS */
c807425
+  N_hkscs_ucs_map,	/* HKSCS-1 */
c807425
+  N_hkscs_ucs_map,	/* HKSCS-2 */
c807425
+};
c807425
+
c807425
 static wc_wchar_t
c807425
 ucs_cs94_conv(wc_ccs ccs, wc_uint16 c)
c807425
 {
c807425
-- 
c807425
cgit v0.12
c807425