浏览代码

Merge pull request #3542 from ms-maxvollmer/fbx_tokenizer_fix

FBXBinaryTokenizer: Check length of property
Kim Kulling 4 年之前
父节点
当前提交
3ccfc03c48
共有 1 个文件被更改,包括 5 次插入0 次删除
  1. 5 0
      code/AssetLib/FBX/FBXBinaryTokenizer.cpp

+ 5 - 0
code/AssetLib/FBX/FBXBinaryTokenizer.cpp

@@ -375,6 +375,11 @@ bool ReadScope(TokenList& output_tokens, const char* input, const char*& cursor,
 
     // now come the individual properties
     const char* begin_cursor = cursor;
+
+    if ((begin_cursor + prop_length) > end) {
+        TokenizeError("property length out of bounds reading length ", input, cursor);
+    }
+
     for (unsigned int i = 0; i < prop_count; ++i) {
         ReadData(sbeg, send, input, cursor, begin_cursor + prop_length);