summaryrefslogtreecommitdiffstats
path: root/media
diff options
context:
space:
mode:
authorMarco Nelissen <marcone@google.com>2015-08-07 14:40:01 +0000
committerAndroid Git Automerger <android-git-automerger@android.com>2015-08-07 14:40:01 +0000
commit578d5b66fc9f5e36ca0cb19b21771aa85ec131ee (patch)
tree52c93dc44e7d204c82fbdd4d34b2480e5f4238f2 /media
parent660620d43898b09126f54a7ca27ca34b011f4726 (diff)
parent171b5fadb9d304f5e06686e4f3d060ef335d7250 (diff)
downloadframeworks_av-578d5b66fc9f5e36ca0cb19b21771aa85ec131ee.zip
frameworks_av-578d5b66fc9f5e36ca0cb19b21771aa85ec131ee.tar.gz
frameworks_av-578d5b66fc9f5e36ca0cb19b21771aa85ec131ee.tar.bz2
am 171b5fad: am d6ea7f65: am f26400c9: Fix crash on malformed id3
* commit '171b5fadb9d304f5e06686e4f3d060ef335d7250': Fix crash on malformed id3
Diffstat (limited to 'media')
-rw-r--r--media/libstagefright/MetaData.cpp32
-rw-r--r--media/libstagefright/id3/ID3.cpp6
2 files changed, 26 insertions, 12 deletions
diff --git a/media/libstagefright/MetaData.cpp b/media/libstagefright/MetaData.cpp
index 7d867b7..1a11c1e 100644
--- a/media/libstagefright/MetaData.cpp
+++ b/media/libstagefright/MetaData.cpp
@@ -244,8 +244,11 @@ MetaData::typed_data::~typed_data() {
MetaData::typed_data::typed_data(const typed_data &from)
: mType(from.mType),
mSize(0) {
- allocateStorage(from.mSize);
- memcpy(storage(), from.storage(), mSize);
+
+ void *dst = allocateStorage(from.mSize);
+ if (dst) {
+ memcpy(dst, from.storage(), mSize);
+ }
}
MetaData::typed_data &MetaData::typed_data::operator=(
@@ -253,8 +256,10 @@ MetaData::typed_data &MetaData::typed_data::operator=(
if (this != &from) {
clear();
mType = from.mType;
- allocateStorage(from.mSize);
- memcpy(storage(), from.storage(), mSize);
+ void *dst = allocateStorage(from.mSize);
+ if (dst) {
+ memcpy(dst, from.storage(), mSize);
+ }
}
return *this;
@@ -271,13 +276,11 @@ void MetaData::typed_data::setData(
clear();
mType = type;
- allocateStorage(size);
- void *dst = storage();
- if (!dst) {
- ALOGE("Couldn't allocate %zu bytes for item", size);
- return;
+
+ void *dst = allocateStorage(size);
+ if (dst) {
+ memcpy(dst, data, size);
}
- memcpy(dst, data, size);
}
void MetaData::typed_data::getData(
@@ -287,14 +290,19 @@ void MetaData::typed_data::getData(
*data = storage();
}
-void MetaData::typed_data::allocateStorage(size_t size) {
+void *MetaData::typed_data::allocateStorage(size_t size) {
mSize = size;
if (usesReservoir()) {
- return;
+ return &u.reservoir;
}
u.ext_data = malloc(mSize);
+ if (u.ext_data == NULL) {
+ ALOGE("Couldn't allocate %zu bytes for item", size);
+ mSize = 0;
+ }
+ return u.ext_data;
}
void MetaData::typed_data::freeStorage() {
diff --git a/media/libstagefright/id3/ID3.cpp b/media/libstagefright/id3/ID3.cpp
index 7f221a0..3ef175b 100644
--- a/media/libstagefright/id3/ID3.cpp
+++ b/media/libstagefright/id3/ID3.cpp
@@ -804,6 +804,12 @@ ID3::getAlbumArt(size_t *length, String8 *mime) const {
size_t descLen = StringSize(&data[2 + mimeLen], encoding);
+ if (size < 2 ||
+ size - 2 < mimeLen ||
+ size - 2 - mimeLen < descLen) {
+ ALOGW("bogus album art sizes");
+ return NULL;
+ }
*length = size - 2 - mimeLen - descLen;
return &data[2 + mimeLen + descLen];