diff options
author | Marco Nelissen <marcone@google.com> | 2015-01-15 14:11:19 -0800 |
---|---|---|
committer | Marco Nelissen <marcone@google.com> | 2015-01-15 14:11:19 -0800 |
commit | d488982887e24f4a8e61f68d945a2f113f43579e (patch) | |
tree | 4ee792cfa25c6f934e223b7bd80f57cc6a0479a1 /media/libstagefright/id3 | |
parent | 73315c1a8b39dcc7b9c8721de6653405503b3a5b (diff) | |
download | frameworks_av-d488982887e24f4a8e61f68d945a2f113f43579e.zip frameworks_av-d488982887e24f4a8e61f68d945a2f113f43579e.tar.gz frameworks_av-d488982887e24f4a8e61f68d945a2f113f43579e.tar.bz2 |
Fix id3 parser crash
Bug: 18872896
Change-Id: I953f58f35a76590701234d5707e060499acfc069
Diffstat (limited to 'media/libstagefright/id3')
-rw-r--r-- | media/libstagefright/id3/ID3.cpp | 11 |
1 files changed, 9 insertions, 2 deletions
diff --git a/media/libstagefright/id3/ID3.cpp b/media/libstagefright/id3/ID3.cpp index d8bfada..d9491d6 100644 --- a/media/libstagefright/id3/ID3.cpp +++ b/media/libstagefright/id3/ID3.cpp @@ -630,7 +630,10 @@ void ID3::Iterator::findFrame() { | (mParent.mData[mOffset + 4] << 8) | mParent.mData[mOffset + 5]; - mFrameSize += 6; + if (mFrameSize == 0) { + return; + } + mFrameSize += 6; // add tag id and size field if (mOffset + mFrameSize > mParent.mSize) { ALOGV("partial frame at offset %zu (size = %zu, bytes-remaining = %zu)", @@ -671,7 +674,11 @@ void ID3::Iterator::findFrame() { baseSize = U32_AT(&mParent.mData[mOffset + 4]); } - mFrameSize = 10 + baseSize; + if (baseSize == 0) { + return; + } + + mFrameSize = 10 + baseSize; // add tag id, size field and flags if (mOffset + mFrameSize > mParent.mSize) { ALOGV("partial frame at offset %zu (size = %zu, bytes-remaining = %zu)", |