From 9af8cfa60f7c0d51e667d62465b6f9eb7d425e1d Mon Sep 17 00:00:00 2001 From: Martin Storsjo Date: Fri, 25 May 2012 19:46:34 +0300 Subject: [PATCH] stagefright aacenc: Fix reading out of bounds in pow2_xy This fixes cases where x was a large number, causing fPart to exceed the 32 bit signed integer range (while fitting in an unsigned 32 bit integer), making the table index a negative number. Change-Id: I674047db65f89148a93d218c138b42cd8305f80e --- media/libstagefright/codecs/aacenc/basic_op/oper_32b.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/media/libstagefright/codecs/aacenc/basic_op/oper_32b.c b/media/libstagefright/codecs/aacenc/basic_op/oper_32b.c index 982f4fd44e6d5..cc019271c158d 100644 --- a/media/libstagefright/codecs/aacenc/basic_op/oper_32b.c +++ b/media/libstagefright/codecs/aacenc/basic_op/oper_32b.c @@ -344,8 +344,8 @@ static const Word32 pow2Table[POW2_TABLE_SIZE] = { */ Word32 pow2_xy(Word32 x, Word32 y) { - Word32 iPart; - Word32 fPart; + UWord32 iPart; + UWord32 fPart; Word32 res; Word32 tmp, tmp2; Word32 shift, shift2;