new game
simgear flightgear opencity
This commit is contained in:
@@ -0,0 +1,27 @@
|
||||
From f485a4e49cddeef436a212bc655799e71a9648a7 Mon Sep 17 00:00:00 2001
|
||||
From: Fabrice Bellet <fabrice@bellet.info>
|
||||
Date: Sun, 22 Sep 2013 11:54:54 +0200
|
||||
Subject: [PATCH 1/3] remove unneeded header
|
||||
|
||||
---
|
||||
simgear/misc/stopwatch.hxx | 4 ----
|
||||
1 file changed, 4 deletions(-)
|
||||
|
||||
diff --git a/simgear/misc/stopwatch.hxx b/simgear/misc/stopwatch.hxx
|
||||
index 3436438..70df459 100644
|
||||
--- a/simgear/misc/stopwatch.hxx
|
||||
+++ b/simgear/misc/stopwatch.hxx
|
||||
@@ -42,10 +42,6 @@
|
||||
# error This library requires C++
|
||||
#endif
|
||||
|
||||
-#ifdef HAVE_CONFIG_H
|
||||
-# include <simgear_config.h>
|
||||
-#endif
|
||||
-
|
||||
#if defined(__linux__) && ! defined(HAVE_GETRUSAGE)
|
||||
# define HAVE_GETRUSAGE
|
||||
#endif
|
||||
--
|
||||
1.8.3.1
|
||||
|
||||
+34
@@ -0,0 +1,34 @@
|
||||
From 26fbf7c70010c7a16bdfe98a3282a13c9defd8b9 Mon Sep 17 00:00:00 2001
|
||||
From: Fabrice Bellet <fabrice@bellet.info>
|
||||
Date: Sun, 22 Sep 2013 11:56:12 +0200
|
||||
Subject: [PATCH 2/3] check to be sure that %n is not being set as format type
|
||||
(CVE-2012-2090)
|
||||
|
||||
---
|
||||
simgear/scene/model/SGText.cxx | 10 ++++++++++
|
||||
1 file changed, 10 insertions(+)
|
||||
|
||||
diff --git a/simgear/scene/model/SGText.cxx b/simgear/scene/model/SGText.cxx
|
||||
index ca065b1..edf80bd 100644
|
||||
--- a/simgear/scene/model/SGText.cxx
|
||||
+++ b/simgear/scene/model/SGText.cxx
|
||||
@@ -76,6 +76,16 @@ void SGText::UpdateCallback::operator()(osg::Node * node, osg::NodeVisitor *nv )
|
||||
// FIXME:
|
||||
// hopefully the users never specifies bad formats here
|
||||
// this should better be something more robust
|
||||
+ // It is never safe for format.c_str to be %n.
|
||||
+ string unsafe ("%n");
|
||||
+ size_t found;
|
||||
+
|
||||
+ found=format.find(unsafe);
|
||||
+ if (found!=string::npos) {
|
||||
+ SG_LOG(SG_GENERAL, SG_ALERT, "format type contained %n, but this is unsafe, reverting to %s");
|
||||
+ format = "%s";
|
||||
+ }
|
||||
+
|
||||
char buf[256];
|
||||
if( numeric ) {
|
||||
double d = property->getDoubleValue() * scale + offset;
|
||||
--
|
||||
1.8.3.1
|
||||
|
||||
Reference in New Issue
Block a user