sanitize variationStore in CFF2 against its size

pull/1457/head
Michiharu Ariza 6 years ago
parent d9dabc00e9
commit c31092ab34
  1. 2
      src/hb-ot-cff2-table.hh

@ -115,7 +115,7 @@ struct CFF2VariationStore
inline bool sanitize (hb_sanitize_context_t *c) const inline bool sanitize (hb_sanitize_context_t *c) const
{ {
TRACE_SANITIZE (this); TRACE_SANITIZE (this);
return_trace (likely (c->check_struct (this)) && varStore.sanitize (c)); return_trace (likely (c->check_struct (this)) && c->check_range (&varStore, size) && varStore.sanitize (c));
} }
inline bool serialize (hb_serialize_context_t *c, const CFF2VariationStore *varStore) inline bool serialize (hb_serialize_context_t *c, const CFF2VariationStore *varStore)

Loading…
Cancel
Save