diff options
author | Joshua J. Drake <android-open-source@qoop.org> | 2015-08-04 03:35:37 +0000 |
---|---|---|
committer | Android Git Automerger <android-git-automerger@android.com> | 2015-08-04 03:35:37 +0000 |
commit | ac7cb990cc4c8a59a945ce36e5702e0adb213db4 (patch) | |
tree | 68d21f765b211b856cd1b8c435839ee13e711cc0 /media | |
parent | 134dc3110c401544e4d3a3a1deab1c131fb77720 (diff) | |
parent | b417986c3a3a6bb9ca33657385a3433ff54090b2 (diff) | |
download | frameworks_av-ac7cb990cc4c8a59a945ce36e5702e0adb213db4.zip frameworks_av-ac7cb990cc4c8a59a945ce36e5702e0adb213db4.tar.gz frameworks_av-ac7cb990cc4c8a59a945ce36e5702e0adb213db4.tar.bz2 |
am b417986c: am d1c08d6b: am efa73c2e: am 2e24d091: am a59d5e66: am 8ef5da3d: am 4dd7cb69: Fix integer underflow in ESDS processing
* commit 'b417986c3a3a6bb9ca33657385a3433ff54090b2':
Fix integer underflow in ESDS processing
Diffstat (limited to 'media')
-rw-r--r-- | media/libstagefright/ESDS.cpp | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/media/libstagefright/ESDS.cpp b/media/libstagefright/ESDS.cpp index 4a0c35c..c76bc4a 100644 --- a/media/libstagefright/ESDS.cpp +++ b/media/libstagefright/ESDS.cpp @@ -136,6 +136,8 @@ status_t ESDS::parseESDescriptor(size_t offset, size_t size) { --size; if (streamDependenceFlag) { + if (size < 2) + return ERROR_MALFORMED; offset += 2; size -= 2; } @@ -145,11 +147,15 @@ status_t ESDS::parseESDescriptor(size_t offset, size_t size) { return ERROR_MALFORMED; } unsigned URLlength = mData[offset]; + if (URLlength >= size) + return ERROR_MALFORMED; offset += URLlength + 1; size -= URLlength + 1; } if (OCRstreamFlag) { + if (size < 2) + return ERROR_MALFORMED; offset += 2; size -= 2; |