RESTRICT AUTOMERGE: Fix vulnerabilities in PduParser
Fix security issues in PduParser where malformed multipart alternative PDUs
can trigger NullPointerException, ArrayIndexOutOfBoundsException, OutOfMemoryError,
or StackOverflowError.
- Prevent StackOverflowError by enforcing a maximum parsing depth of 30.
- Prevent OutOfMemoryError by verifying dataLength does not exceed available bytes in stream.
- Prevent NullPointerException and ArrayIndexOutOfBoundsException by verifying childParts
exist before trying to retrieve the first child.
- Optimize skipWapValue and parameter skipping to use InputStream.skip instead of
allocating temporary byte arrays.
Bug: 513581684
Flag: EXEMPT BUGFIX
Test: atest TelephonyCommonTests:PduParserTest
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:8054772bc46861a760c8539bec7a1c87d9ef2b44
Merged-In: If97a6540b86380a01700fca887813ff117922e58
Change-Id: If97a6540b86380a01700fca887813ff117922e58
2 files changed