[ 
https://issues.apache.org/jira/browse/IO-825?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Gary D. Gregory resolved IO-825.
--------------------------------
    Fix Version/s: 2.15.2
       Resolution: Fixed

> Some methods in EndianUtils throws IndexOutOfBoundsException when the 
> provided byte array does not have enough data
> -------------------------------------------------------------------------------------------------------------------
>
>                 Key: IO-825
>                 URL: https://issues.apache.org/jira/browse/IO-825
>             Project: Commons IO
>          Issue Type: Bug
>            Reporter: Sheung Chi Chan
>            Priority: Minor
>             Fix For: 2.15.2
>
>
> In `EndianUtils` class, the method for handling *_swappedShort_* / 
> *_swappedInteger_* / *_swappedLong_* from or to byte array assumes that the 
> byte array still has enough space or data with the provided offset for an 
> Integer / Long / Short reading or writing. Thus a byte array with a much 
> shorter length could make the code throw IndexOutOfBoundsException. A 
> possible fix is adding a validation to ensure the byte array has enough data 
> space before processing.
> Some example code snippets are attached below.
> {code:java}
> public static void writeSwappedInteger(final byte[] data, final int offset, 
> final int value) {
>     data[offset + 0] = (byte) (value >> 0 & 0xff);
>     data[offset + 1] = (byte) (value >> 8 & 0xff);
>     data[offset + 2] = (byte) (value >> 16 & 0xff);
>     data[offset + 3] = (byte) (value >> 24 & 0xff);
> } {code}
> {code:java}
> public static int readSwappedUnsignedShort(final byte[] data, final int 
> offset) {
>     return ((data[offset + 0] & 0xff) << 0) + ((data[offset + 1] & 0xff) << 
> 8);
> }
> {code}



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to