summaryrefslogtreecommitdiffstats
path: root/media/libstagefright
diff options
context:
space:
mode:
authorMarco Nelissen <marcone@google.com>2016-02-23 14:48:46 -0800
committerThe Android Automerger <android-build@google.com>2016-02-26 16:56:01 -0800
commit582c02ea5c9c8db5f993d784a0a85b275b2e59fd (patch)
treea1da00dc7587665f1a1cf1b48fbb67a89aa2de2b /media/libstagefright
parent3a90a02bb6c4e8352112dbb9f2316935e4dd7315 (diff)
downloadframeworks_av-582c02ea5c9c8db5f993d784a0a85b275b2e59fd.zip
frameworks_av-582c02ea5c9c8db5f993d784a0a85b275b2e59fd.tar.gz
frameworks_av-582c02ea5c9c8db5f993d784a0a85b275b2e59fd.tar.bz2
Also fix out of bounds access for normal read
Previous fix accidentally only fixed the fragmented read case. Bug: 27208621 Change-Id: Ie16f1920b84c8aba613842659238fcd5925694ad
Diffstat (limited to 'media/libstagefright')
-rwxr-xr-xmedia/libstagefright/MPEG4Extractor.cpp10
1 files changed, 9 insertions, 1 deletions
diff --git a/media/libstagefright/MPEG4Extractor.cpp b/media/libstagefright/MPEG4Extractor.cpp
index e4f8384..f8789da 100755
--- a/media/libstagefright/MPEG4Extractor.cpp
+++ b/media/libstagefright/MPEG4Extractor.cpp
@@ -4228,7 +4228,15 @@ status_t MPEG4Source::read(
continue;
}
- CHECK(dstOffset + 4 <= mBuffer->size());
+ if (dstOffset > SIZE_MAX - 4 ||
+ dstOffset + 4 > SIZE_MAX - nalLength ||
+ dstOffset + 4 + nalLength > mBuffer->size()) {
+ ALOGE("b/27208621 : %zu %zu", dstOffset, mBuffer->size());
+ android_errorWriteLog(0x534e4554, "27208621");
+ mBuffer->release();
+ mBuffer = NULL;
+ return ERROR_MALFORMED;
+ }
dstData[dstOffset++] = 0;
dstData[dstOffset++] = 0;