Fix signed overflow in convertCleanApertureToRect In HeifCleanAperture.cpp:convertCleanApertureToRect(), centerX.getInt32() and centerY.getInt32() are added with clapW and clapH respectively to calculate the right and bottom coordinates. This signed-integer addition can overflow int32_t with maliciously crafted CleanAperture values, causing an IntSan abort in the media.extractor process. Prevent the overflow by validating bounds using safe int64_t arithmetic prior to performing the addition. Bug: 503550257 Test: atest HeifCleanApertureUnitTest --host Flag: EXEMPT BUGFIX Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:5fcd67a562a2dffdfaf25f35c7acf805a96ac8ae Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:91c2a108e4ef9dda4e27c4b83b7fafc76b09cd55 Merged-In: I2b282fc9e69a6510e9414fd2bbfe3beddf81001e Change-Id: I2b282fc9e69a6510e9414fd2bbfe3beddf81001e