[media] Fix heap-buffer-overflow in AudioAttributes unmarshalling

This CL fixes a heap-buffer-overflow in MediaPlayerService's AudioAttributes
unmarshalling logic. The source length was in bytes and the
utf16_to_utf8 uses char16_t pointer arithmetic on it that would lead to
an OOB read. Corrected the source length parameter to give length as
number of char16_t.
The destination length has to be 1 less than the actual size of the
destination since utf16_to_utf8 adds a NULL terminator. Correct this
behaviour to limit the destination length to allocated length - 1.

Bug: 482172329
Bug: 396471524

Test: fuzzer with the testcases
Test: atest CtsMediaAudioTestCases CtsMediaPlayerTestCases libutils_tests

Flag: EXEMPT CVE_FIX
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:50d6c98e00c2c5620ea50e26c9c44e70a0c5ce8a
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:8926da1d9c9db3031bc8a7075927c3ebec3292cd
Merged-In: I9f607d57281c76d8e1c1a14112dffdf22acb8080
Change-Id: I9f607d57281c76d8e1c1a14112dffdf22acb8080
1 file changed