Tianjie Xu f616da1726 DO NOT MERGE: Add a checker for signature boundary in verifier
The 'signature_start' variable marks the location of the signature
from the end of a zip archive. And a boundary check is missing where
'signature_start' should be within the EOCD comment field. This causes
problems when sideloading a malicious package. Also add a corresponding
test.

Bug: 31914369
Test: Verification fails correctly when sideloading recovery_test.zip on
angler.

Change-Id: I6ea96bf04dac5d8d4d6719e678d504f957b4d5c1
(cherry-picked from f69e6a9475)
(cherry picked from commit 54ea136fde)
2016-12-19 16:46:44 -08:00
2013-07-09 12:50:24 -07:00
2013-09-11 13:24:32 -07:00
2013-03-07 13:34:24 -08:00
2016-05-17 20:28:54 +00:00
2012-01-10 10:18:17 -08:00
2012-01-10 10:18:17 -08:00
2012-08-22 17:26:40 -07:00
2013-07-31 11:35:12 -07:00
S
Description
No description provided
102 MiB
Languages
C++ 50.2%
C 43.6%
Makefile 1.9%
Java 1.8%
Roff 1%
Other 1.4%