[media] Fix heap-buffer-overflow in AudioAttributes unmarshalling This CL fixes a heap-buffer-overflow in MediaPlayerService's AudioAttributes unmarshalling logic. The source length was in bytes and the utf16_to_utf8 uses char16_t pointer arithmetic on it that would lead to an OOB read. Corrected the source length parameter to give length as number of char16_t. The destination length has to be 1 less than the actual size of the destination since utf16_to_utf8 adds a NULL terminator. Correct this behaviour to limit the destination length to allocated length - 1. Bug: 482172329 Bug: 396471524 Test: fuzzer with the testcases Test: atest CtsMediaAudioTestCases CtsMediaPlayerTestCases libutils_tests Flag: EXEMPT CVE_FIX Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:50d6c98e00c2c5620ea50e26c9c44e70a0c5ce8a Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:8926da1d9c9db3031bc8a7075927c3ebec3292cd Merged-In: I9f607d57281c76d8e1c1a14112dffdf22acb8080 Change-Id: I9f607d57281c76d8e1c1a14112dffdf22acb8080