aboutsummaryrefslogtreecommitdiff
path: root/engines/titanic
diff options
context:
space:
mode:
authorPaul Gilbert2017-07-18 22:44:55 -0400
committerPaul Gilbert2017-07-18 22:44:55 -0400
commit559e6dafe1ea9c57dddca65d8e16e94ba88a4c40 (patch)
treefd73e1fe1dbdc8ff7a72e8add1e4ad26305fb119 /engines/titanic
parent60de2718bddeb1c14b3ec031d3a9fcc931bd38a3 (diff)
downloadscummvm-rg350-559e6dafe1ea9c57dddca65d8e16e94ba88a4c40.tar.gz
scummvm-rg350-559e6dafe1ea9c57dddca65d8e16e94ba88a4c40.tar.bz2
scummvm-rg350-559e6dafe1ea9c57dddca65d8e16e94ba88a4c40.zip
TITANIC: Fix access after free in filterConcepts loop
Diffstat (limited to 'engines/titanic')
-rw-r--r--engines/titanic/true_talk/tt_parser.cpp4
1 files changed, 3 insertions, 1 deletions
diff --git a/engines/titanic/true_talk/tt_parser.cpp b/engines/titanic/true_talk/tt_parser.cpp
index 2893c50a8d..adf008767f 100644
--- a/engines/titanic/true_talk/tt_parser.cpp
+++ b/engines/titanic/true_talk/tt_parser.cpp
@@ -1609,7 +1609,9 @@ bool TTparser::checkConcept2(TTconcept *concept, int conceptMode) {
int TTparser::filterConcepts(int conceptMode, int conceptIndex) {
int result = 0;
- for (TTconcept *currP = _conceptP; currP && !result; currP = currP->_nextP) {
+ for (TTconcept *nextP, *currP = _conceptP; currP && !result; currP = nextP) {
+ nextP = currP->_nextP;
+
if (checkConcept2(currP, conceptMode)) {
TTconcept **ptrPP = _sentenceConcept->setConcept(conceptIndex, currP);
TTconcept *newConcept = new TTconcept(*currP);