浏览代码

Prevented looking up incorrect object handles.

Previously, dAtoi would be called on arbitrary strings delimited
only by the / character. Now, Sim::findObject actually checks that
object handles (strings starting with a digit) actually only contain
digits or slashes.
Daniel Buckmaster 13 年之前
父节点
当前提交
46f140710a
共有 1 个文件被更改,包括 2 次插入0 次删除
  1. 2 0
      Engine/source/console/simManager.cpp

+ 2 - 0
Engine/source/console/simManager.cpp

@@ -367,6 +367,8 @@ SimObject* findObject(const char* name)
                return NULL;
             return obj->findObject(temp);
          }
+         else if (c < '0' || c > '9')
+            return NULL;
       }
    }
    S32 len;