summaryrefslogtreecommitdiffstats
path: root/media
diff options
context:
space:
mode:
authorJoshua J. Drake <android-open-source@qoop.org>2015-08-04 03:25:53 +0000
committerAndroid Git Automerger <android-git-automerger@android.com>2015-08-04 03:25:53 +0000
commitb417986c3a3a6bb9ca33657385a3433ff54090b2 (patch)
tree57e3a62d0feff6a757224f8a071fa00db2889e59 /media
parent80a6d9f37571c89905b8ae4074529a960a5f2194 (diff)
parentd1c08d6bff6d1936cf0e9cbfa5054128f5280ef3 (diff)
downloadframeworks_av-b417986c3a3a6bb9ca33657385a3433ff54090b2.zip
frameworks_av-b417986c3a3a6bb9ca33657385a3433ff54090b2.tar.gz
frameworks_av-b417986c3a3a6bb9ca33657385a3433ff54090b2.tar.bz2
am d1c08d6b: am efa73c2e: am 2e24d091: am a59d5e66: am 8ef5da3d: am 4dd7cb69: Fix integer underflow in ESDS processing
* commit 'd1c08d6bff6d1936cf0e9cbfa5054128f5280ef3': Fix integer underflow in ESDS processing
Diffstat (limited to 'media')
-rw-r--r--media/libstagefright/ESDS.cpp6
1 files changed, 6 insertions, 0 deletions
diff --git a/media/libstagefright/ESDS.cpp b/media/libstagefright/ESDS.cpp
index 4a0c35c..c76bc4a 100644
--- a/media/libstagefright/ESDS.cpp
+++ b/media/libstagefright/ESDS.cpp
@@ -136,6 +136,8 @@ status_t ESDS::parseESDescriptor(size_t offset, size_t size) {
--size;
if (streamDependenceFlag) {
+ if (size < 2)
+ return ERROR_MALFORMED;
offset += 2;
size -= 2;
}
@@ -145,11 +147,15 @@ status_t ESDS::parseESDescriptor(size_t offset, size_t size) {
return ERROR_MALFORMED;
}
unsigned URLlength = mData[offset];
+ if (URLlength >= size)
+ return ERROR_MALFORMED;
offset += URLlength + 1;
size -= URLlength + 1;
}
if (OCRstreamFlag) {
+ if (size < 2)
+ return ERROR_MALFORMED;
offset += 2;
size -= 2;