From 4a8f1839eafeaf107ea3b3f59c35137116e69712 Mon Sep 17 00:00:00 2001 From: rdb Date: Thu, 1 Dec 2016 17:36:38 +0100 Subject: [PATCH 1/2] 1.9: change to support .whl distribution (putting panda DLLs in panda3d/ dir) --- .../extensions_native/extension_native_helpers.py | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/direct/src/extensions_native/extension_native_helpers.py b/direct/src/extensions_native/extension_native_helpers.py index 20afc7ddef..e17457b872 100644 --- a/direct/src/extensions_native/extension_native_helpers.py +++ b/direct/src/extensions_native/extension_native_helpers.py @@ -50,9 +50,18 @@ if sys.platform == "win32": filename = "libpandaexpress%s%s" % (dll_suffix, dll_ext) for dir in sys.path + [sys.prefix]: lib = os.path.join(dir, filename) - if (os.path.exists(lib)): + if os.path.exists(lib): target = dir - if target == None: + + # Perhaps it is in the same directory as panda3d/core.pyd ? + if target is None: + for dir in sys.path: + lib = os.path.join(dir, 'panda3d', filename) + if os.path.exists(lib): + target = os.path.join(dir, 'panda3d') + break + + if target is None: message = "Cannot find %s" % (filename) raise ImportError(message) From 2b6e192e5aeb9c1b5078815c15735698f4ed1b6b Mon Sep 17 00:00:00 2001 From: rdb Date: Sat, 3 Dec 2016 01:04:35 +0100 Subject: [PATCH 2/2] Protect against overallocation when reading corrupt texture from bam --- panda/src/gobj/texture.cxx | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/panda/src/gobj/texture.cxx b/panda/src/gobj/texture.cxx index fa16fa7ab8..bcabaa7a8c 100644 --- a/panda/src/gobj/texture.cxx +++ b/panda/src/gobj/texture.cxx @@ -8271,6 +8271,14 @@ do_fillin_body(CData *cdata, DatagramIterator &scan, BamReader *manager) { cdata->_simple_image_date_generated = scan.get_int32(); size_t u_size = scan.get_uint32(); + + // Protect against large allocation. + if (u_size > scan.get_remaining_size()) { + gobj_cat.error() + << "simple RAM image extends past end of datagram, is texture corrupt?\n"; + return; + } + PTA_uchar image = PTA_uchar::empty_array(u_size, get_class_type()); scan.extract_bytes(image.p(), u_size); @@ -8327,6 +8335,14 @@ do_fillin_rawdata(CData *cdata, DatagramIterator &scan, BamReader *manager) { // fill the cdata->_image buffer with image data size_t u_size = scan.get_uint32(); + + // Protect against large allocation. + if (u_size > scan.get_remaining_size()) { + gobj_cat.error() + << "RAM image " << n << " extends past end of datagram, is texture corrupt?\n"; + return; + } + PTA_uchar image = PTA_uchar::empty_array(u_size, get_class_type()); scan.extract_bytes(image.p(), u_size);