)]}'
{
  "commit": "5874d9e7959d3dbcdd7b3a5d256a74dc4fc17f2b",
  "tree": "8c408750fc96f12b335b3de21694f19eea5bb668",
  "parents": [
    "ba14cc5ce9ae6fc7e7211e1a6eb334973a889679"
  ],
  "author": {
    "name": "Jean-Michel Trivi",
    "email": "jmtrivi@google.com",
    "time": "Mon Oct 30 11:31:03 2017 -0700"
  },
  "committer": {
    "name": "android-build-team Robot",
    "email": "android-build-team-robot@google.com",
    "time": "Wed Nov 29 18:06:10 2017 +0000"
  },
  "message": "Fix out of bound memory access in lppTransposer\n\nIn TRANSPOSER_SETTINGS, initialize the whole bwBorders array to a\n  reasonable value to guarantee correct termination in while loop\n  in lppTransposer function. This fixes the reported bug.\nFor completeness:\n  - clear the whole bwIndex array instead of noOfPatches entries only.\n  - abort criterion in while loop to prevent potential\n    infinite loop, and limit bwIndex[patch] to a valid range.\n\nTest: see bug for malicious content, decoded with \"stagefright -s -a\"\nBug: 65280786\n\nChange-Id: I16ed2e1c0f1601926239a652ca20a91284151843\n(cherry picked from commit 6d3dd40e204bf550abcfa589bd9615df8778e118)\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "117e7390c2461018155b708541769d8914c22c0d",
      "old_mode": 33188,
      "old_path": "libSBRdec/src/lpp_tran.cpp",
      "new_id": "343aec3c1bb4fe8c03de738966b22d3ba9b2be55",
      "new_mode": 33188,
      "new_path": "libSBRdec/src/lpp_tran.cpp"
    }
  ]
}
