ResStringPool: Validate styleCount and offsets

ResStringPool::setTo fails to validate that the style-index array fits
within the data chunk when stringCount is zero, as it was skipping
validation of stringsStart. An attacker could craft a ResStringPool
with a large styleCount and a huge stringsStart, bypassing current
checks and leading to an OOB heap read in ResStringPool::styleAt.

This change:
1. Validates stringsStart and stylesStart against the total size early.
2. Improves the styleCount bounds check to ensure the style offset array
   fits within the chunk and doesn't overlap with string data.

Bug: 499091487
Test: atest libandroidfw_tests --host
Flag: EXEMPT BUGFIX

(cherry picked from commit 968cb0736ca65b22a3c7230820912adffa452b1e)
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:0aa6ef39a4277197f1a216904fcb8e1c034c4299
Merged-In: I3e1e4579fbda8ee89c5fea3945d523c6e5b72dc9
Change-Id: I3e1e4579fbda8ee89c5fea3945d523c6e5b72dc9
2 files changed