fix: closes #6069 CVE-2025-3196 (#6154)

* fix: closes #6069 CVE-2025-3196

* fix: updated patch for upstream symbol names

* fix: warning C4267

---------

Co-authored-by: Vinz Jarl Valentin Spring <vinzs@amazon.com>
Co-authored-by: Kim Kulling <kimkulling@users.noreply.github.com>
Co-authored-by: Vinz Spring <contact@vinzspring.de>
This commit is contained in:
Vinz Spring
2025-05-31 14:27:10 +02:00
committed by GitHub
parent 7b38feb8a7
commit 7eb6b0c3db

View File

@@ -319,16 +319,22 @@ void MD2Importer::InternReadFile( const std::string& pFile,
clr.b = clr.g = clr.r = 0.05f;
pcHelper->AddProperty<aiColor3D>(&clr, 1,AI_MATKEY_COLOR_AMBIENT);
if (pcSkins->name[0])
const ai_uint32 MaxNameLength = AI_MAXLEN - 1; // one byte reserved for \0
ai_uint32 iLen = static_cast<ai_uint32>(::strlen(pcSkins->name));
bool nameTooLong = iLen > MaxNameLength;
if (pcSkins->name[0] && !nameTooLong)
{
aiString szString;
const ai_uint32 iLen = (ai_uint32) ::strlen(pcSkins->name);
::memcpy(szString.data,pcSkins->name,iLen);
::memcpy(szString.data, pcSkins->name, iLen);
szString.data[iLen] = '\0';
szString.length = iLen;
pcHelper->AddProperty(&szString,AI_MATKEY_TEXTURE_DIFFUSE(0));
}
else if (nameTooLong) {
ASSIMP_LOG_WARN("Texture file name is too long. It will be skipped.");
}
else{
ASSIMP_LOG_WARN("Texture file name has zero length. It will be skipped.");
}