Fix signed overflow in convertCleanApertureToRect

In HeifCleanAperture.cpp:convertCleanApertureToRect(),
centerX.getInt32() and centerY.getInt32() are added with clapW and
clapH respectively to calculate the right and bottom coordinates.
This signed-integer addition can overflow int32_t with maliciously
crafted CleanAperture values, causing an IntSan abort in the
media.extractor process.

Prevent the overflow by validating bounds using safe int64_t arithmetic
prior to performing the addition.

Bug: 503550257
Test: atest HeifCleanApertureUnitTest --host
Flag: EXEMPT BUGFIX
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:5fcd67a562a2dffdfaf25f35c7acf805a96ac8ae
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:91c2a108e4ef9dda4e27c4b83b7fafc76b09cd55
Merged-In: I2b282fc9e69a6510e9414fd2bbfe3beddf81001e
Change-Id: I2b282fc9e69a6510e9414fd2bbfe3beddf81001e
2 files changed