Index: includes/bootstrap.inc
===================================================================
RCS file: /cvs/drupal/drupal/includes/bootstrap.inc,v
retrieving revision 1.433
diff -u -p -r1.433 bootstrap.inc
--- includes/bootstrap.inc	25 Oct 2010 00:06:19 -0000	1.433
+++ includes/bootstrap.inc	28 Oct 2010 17:33:12 -0000
@@ -499,6 +499,12 @@ function drupal_environment_initialize()
     $_SERVER['HTTP_HOST'] = '';
   }
 
+  // Check for invalid UTF-8 in input.
+  if (!drupal_valid_server_input($_GET) || !drupal_valid_server_input($_POST) || !drupal_valid_server_input($_COOKIE) || !drupal_valid_server_input($_FILES)) {
+    header($_SERVER['SERVER_PROTOCOL'] . ' 400 Bad Request');
+    exit;
+  }
+
   // When clean URLs are enabled, emulate ?q=foo/bar using REQUEST_URI. It is
   // not possible to append the query string using mod_rewrite without the B
   // flag (this was added in Apache 2.2.8), because mod_rewrite unescapes the
@@ -543,6 +549,32 @@ function drupal_valid_http_host($host) {
 }
 
 /**
+ * Check server input for invalid UTF-8.
+ */
+function drupal_valid_server_input($array) {
+  if (!isset($array)) {
+    return TRUE;
+  }
+  foreach ($array as $key => $value) {
+    // Validate the key.
+    if (!drupal_validate_utf8($key)) {
+      return FALSE;
+    }
+    // Validate the value.
+    // If the value is an array, recurse into it.
+    if (is_array($value)) {
+      if (!drupal_valid_server_input($value)) {
+        return FALSE;
+      }
+    }
+    elseif (!drupal_validate_utf8($value)) {
+      return FALSE;
+    }
+  }
+  return TRUE;
+}
+
+/**
  * Loads the configuration and sets the base URL, cookie domain, and
  * session name correctly.
  */
