Explorar o código

Merge branch 'master' into fix-gltf-bin-from-memory

Kim Kulling %!s(int64=4) %!d(string=hai) anos
pai
achega
e0803b3ec2
Modificáronse 1 ficheiros con 5 adicións e 0 borrados
  1. 5 0
      code/AssetLib/FBX/FBXBinaryTokenizer.cpp

+ 5 - 0
code/AssetLib/FBX/FBXBinaryTokenizer.cpp

@@ -375,6 +375,11 @@ bool ReadScope(TokenList& output_tokens, const char* input, const char*& cursor,
 
     // now come the individual properties
     const char* begin_cursor = cursor;
+
+    if ((begin_cursor + prop_length) > end) {
+        TokenizeError("property length out of bounds reading length ", input, cursor);
+    }
+
     for (unsigned int i = 0; i < prop_count; ++i) {
         ReadData(sbeg, send, input, cursor, begin_cursor + prop_length);