According to http://unicode.org/forum/viewtopic.php?f=9&t=90 - summarized at http://stackoverflow.com/questions/2685004/why-does-unicode-org-no-longer-offer-a-reference-utf-8-16-32-converter . ConvertUTF is obsolete and buggy. According to discussion at https://lists.debian.org/debian-legal/2006/01/msg00534.html, Richard Stallman and the Unicode consortium has noth acknowledged compatibility issues with licensing of the code - issues has been solved for _later_ code releases issued by the Unicode consortium, but according to https://web.archive.org/web/20081228105917/http://www.unicode.org/Public/PROGRAMS/CVTUTF/ there has been no newer release of ConvertUTF since 2004.
This is only used by the pdfwrite device to convert UTF-16BE into UTF-8, and then only when we get an XMP pdfamrk with the data encoded in UTF-16BE. Its really rarely used so I'm not hugely keen on spending a lot of time on this. I doubt its bugginess affects us significantly. As regards the licence, the discussion makes it clear that the intent of the code was to be used as example code, which pretty much implies permission to modify. Granted it doesn't explicitly say so. The only real solution to this is to write our own implementation, which I guess I'll look into at some point. I don't regard this as critical though.
Fixed in commit 273a1331138ee5702e7eb6409a853c598211b2 which does some other tidying up as well.