From 8704782bb426a953ccc4bcbfbfb711b5b76e5ee4 Mon Sep 17 00:00:00 2001 From: Nicky Date: Sat, 29 Dec 2012 18:55:51 +0100 Subject: [PATCH] Crashfix; make sure spellcheck does not run past end of string buffer. --- indra/llui/lltextbase.cpp | 22 ++++++++++++++++++---- 1 file changed, 18 insertions(+), 4 deletions(-) diff --git a/indra/llui/lltextbase.cpp b/indra/llui/lltextbase.cpp index 2832410809..e431ed6f29 100644 --- a/indra/llui/lltextbase.cpp +++ b/indra/llui/lltextbase.cpp @@ -632,11 +632,14 @@ void LLTextBase::drawText() } // Iterate over all words in the text block and check them one by one - while (word_start < seg_end) + // while (word_start < seg_end) + while ( word_start < wstrText.length() && word_start < seg_end ) // Do not run past end of wstrTest { // Find the end of the current word (special case handling for "'" when it's used as a contraction) word_end = word_start + 1; - while ( (word_end < seg_end) && + + // while ( (word_end < seg_end) && + while ( (word_end < seg_end) && word_end < wstrText.length() && // Don't run past end of wstrText ((LLWStringUtil::isPartOfWord(wstrText[word_end])) || ((L'\'' == wstrText[word_end]) && (LLStringOps::isAlnum(wstrText[word_end - 1])) && (LLStringOps::isAlnum(wstrText[word_end + 1])))) ) @@ -648,16 +651,27 @@ void LLTextBase::drawText() break; } + // Exit if we ran past end of string + if( word_start >= wstrText.length() || word_end >= wstrText.length() ) + break; + // + // Don't process words shorter than 3 characters + std::string word = wstring_to_utf8str(wstrText.substr(word_start, word_end - word_start)); if ( (word.length() >= 3) && (!LLSpellChecker::instance().checkSpelling(word)) ) { mMisspellRanges.push_back(std::pair(word_start, word_end)); } - + // Find the start of the next word word_start = word_end + 1; - while ( (word_start < seg_end) && (!LLWStringUtil::isPartOfWord(wstrText[word_start])) ) + + // Do not run past end of string. + + // while ( (word_start < seg_end) && (!LLWStringUtil::isPartOfWord(wstrText[word_start])) ) + while ( word_start < wstrText.length() && (word_start < seg_end) && (!LLWStringUtil::isPartOfWord(wstrText[word_start])) ) + // { word_start++; }