* A security researcher crafted a gif that would cause the Android
Bitmap code to throw an NPE. That would cause messaging to crash when
decoding the NPE. The frameworks team is changing the underlying code to
throw an OutOfMemoryError instead of a NullPointerException.
In order to catch both errors, the code needs to catch Throwable.
Test: I added code to GifImageResource.getDrawable to throw a new
OutOfMemoryError and then used the debugger to verify it was caught by the
new catch Throwable statement. I did the same test with NullPointerException.
I tested attaching gif images and sending them to verify the gif path still
worked.
BUG=37742976
Change-Id: If71a7e65f8c0b083fe6c4b79f78358666338d59d
* A security researcher crafted a gif that would cause the Android
Bitmap code to throw an NPE. That would cause messaging to crash when
decoding the NPE. Catch the NPE.
Test: manually tested the "crash.gif" attached to the bug. Stepped
through the debugger to verify we're catching the NPE and logging
the attempt. Verified normal gifs still work.
BUG=37742976
Change-Id: Iab814d5b0b514bed0cecddd9a76f1fc095f90892
For platforms with insecure handling of media files, media files should
be opened only after the user chooses to play the media.
Change-Id: I5f9bbd1f8468a704a5962f0dddd3c8b11bba8bea