Reviewed by Maciej.
authordarin <darin@268f45cc-cd09-0410-ab3c-d52691b4dbfc>
Tue, 10 Aug 2004 03:05:37 +0000 (03:05 +0000)
committerdarin <darin@268f45cc-cd09-0410-ab3c-d52691b4dbfc>
Tue, 10 Aug 2004 03:05:37 +0000 (03:05 +0000)
commite37f1fde49b17b29f4b6674da98a57d0b63751cd
treec4b50a60dff1f39c1d5ffbe1bc24370bd4975c1a
parent20fd47dde89f454da949e5fb2c2712af1c299d90
    Reviewed by Maciej.

        - fixed <rdar://problem/3753467> REGRESSION (137-138): reproducible buffer overrun in UString manipulation code

        * kjs/ustring.cpp: (KJS::UString::append): Fix incorrect size computation. Without it
        we get a buffer overflow.

git-svn-id: https://svn.webkit.org/repository/webkit/trunk@7216 268f45cc-cd09-0410-ab3c-d52691b4dbfc
JavaScriptCore/ChangeLog
JavaScriptCore/kjs/ustring.cpp