In checkAccess of MediaProvider.java, there is a possible file deletion due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"83227273977673201952415963432411165056",
"240530743924061286780788861302376556044",
"6043250738476881819042753626898801111",
"35809543942109625896991360514551123473"
]
},
"id": "ASB-A-221855295-1d378eec",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/b18f2972ac20d5c086df3d645dd8518f4cead29b",
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"251272552318062483375803532600811265251",
"109158918448858443125635452458075127604",
"138587773904233750919147985483441127650",
"195309320759852002081564118618854052551",
"245237118464282618670486643864373561354",
"239923988918611491819555322259343837757",
"334522434390633449750374019879302161059",
"284145369461894307536698195442534463170",
"156136969244990530431219627204875887987",
"289313048140665975705991099574537254387",
"5685128272666654397818596601519487550"
]
},
"id": "ASB-A-221855295-338cde89",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/b18f2972ac20d5c086df3d645dd8518f4cead29b",
"target": {
"file": "src/com/android/providers/media/util/FileUtils.java"
}
},
{
"digest": {
"length": 1112.0,
"function_hash": "204881092998669550345217478148577572159"
},
"id": "ASB-A-221855295-7dd2cf8b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/b18f2972ac20d5c086df3d645dd8518f4cead29b",
"target": {
"function": "computeDataFromValues",
"file": "src/com/android/providers/media/util/FileUtils.java"
}
},
{
"digest": {
"length": 269.0,
"function_hash": "149005686500020152072408424580414043116"
},
"id": "ASB-A-221855295-c190036a",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/b18f2972ac20d5c086df3d645dd8518f4cead29b",
"target": {
"function": "deleteIfAllowed",
"file": "src/com/android/providers/media/MediaProvider.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/b18f2972ac20d5c086df3d645dd8518f4cead29b"
],
"types": [
"EoP"
],
"spl": "2022-09-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"83227273977673201952415963432411165056",
"240530743924061286780788861302376556044",
"6043250738476881819042753626898801111",
"35809543942109625896991360514551123473"
]
},
"id": "ASB-A-221855295-5f90af00",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/9af1c783ee7332dd7dbb74252fd357308cb89891",
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
}
},
{
"digest": {
"length": 269.0,
"function_hash": "149005686500020152072408424580414043116"
},
"id": "ASB-A-221855295-7b835316",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/9af1c783ee7332dd7dbb74252fd357308cb89891",
"target": {
"function": "deleteIfAllowed",
"file": "src/com/android/providers/media/MediaProvider.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"239923988918611491819555322259343837757",
"334522434390633449750374019879302161059",
"284145369461894307536698195442534463170",
"156136969244990530431219627204875887987",
"289313048140665975705991099574537254387",
"5685128272666654397818596601519487550"
]
},
"id": "ASB-A-221855295-8289a86f",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/9af1c783ee7332dd7dbb74252fd357308cb89891",
"target": {
"file": "src/com/android/providers/media/util/FileUtils.java"
}
},
{
"digest": {
"length": 968.0,
"function_hash": "183975693316331404397545371747082956439"
},
"id": "ASB-A-221855295-9ddcd1ca",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/9af1c783ee7332dd7dbb74252fd357308cb89891",
"target": {
"function": "computeDataFromValues",
"file": "src/com/android/providers/media/util/FileUtils.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/9af1c783ee7332dd7dbb74252fd357308cb89891"
],
"types": [
"EoP"
],
"spl": "2022-09-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 1112.0,
"function_hash": "204881092998669550345217478148577572159"
},
"id": "ASB-A-221855295-1df96ee3",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/47767be45f3486cb59b3c19c4296b38a0408dccb",
"target": {
"function": "computeDataFromValues",
"file": "src/com/android/providers/media/util/FileUtils.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"83227273977673201952415963432411165056",
"240530743924061286780788861302376556044",
"6043250738476881819042753626898801111",
"35809543942109625896991360514551123473"
]
},
"id": "ASB-A-221855295-5433c79b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/47767be45f3486cb59b3c19c4296b38a0408dccb",
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
}
},
{
"digest": {
"length": 269.0,
"function_hash": "149005686500020152072408424580414043116"
},
"id": "ASB-A-221855295-821778be",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/47767be45f3486cb59b3c19c4296b38a0408dccb",
"target": {
"function": "deleteIfAllowed",
"file": "src/com/android/providers/media/MediaProvider.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"251272552318062483375803532600811265251",
"109158918448858443125635452458075127604",
"138587773904233750919147985483441127650",
"195309320759852002081564118618854052551",
"245237118464282618670486643864373561354",
"239923988918611491819555322259343837757",
"334522434390633449750374019879302161059",
"284145369461894307536698195442534463170",
"156136969244990530431219627204875887987",
"289313048140665975705991099574537254387",
"5685128272666654397818596601519487550"
]
},
"id": "ASB-A-221855295-c1e1e590",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/47767be45f3486cb59b3c19c4296b38a0408dccb",
"target": {
"file": "src/com/android/providers/media/util/FileUtils.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/47767be45f3486cb59b3c19c4296b38a0408dccb"
],
"types": [
"EoP"
],
"spl": "2022-09-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 1112.0,
"function_hash": "204881092998669550345217478148577572159"
},
"id": "ASB-A-221855295-144cb072",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/ac1ccd49fe0e2b8f7de2e391d4f597ce56de53da",
"target": {
"function": "computeDataFromValues",
"file": "src/com/android/providers/media/util/FileUtils.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"83227273977673201952415963432411165056",
"240530743924061286780788861302376556044",
"6043250738476881819042753626898801111",
"35809543942109625896991360514551123473"
]
},
"id": "ASB-A-221855295-b3fb6e59",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/ac1ccd49fe0e2b8f7de2e391d4f597ce56de53da",
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
}
},
{
"digest": {
"length": 269.0,
"function_hash": "149005686500020152072408424580414043116"
},
"id": "ASB-A-221855295-ca99e207",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/ac1ccd49fe0e2b8f7de2e391d4f597ce56de53da",
"target": {
"function": "deleteIfAllowed",
"file": "src/com/android/providers/media/MediaProvider.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"251272552318062483375803532600811265251",
"109158918448858443125635452458075127604",
"138587773904233750919147985483441127650",
"195309320759852002081564118618854052551",
"245237118464282618670486643864373561354",
"239923988918611491819555322259343837757",
"334522434390633449750374019879302161059",
"284145369461894307536698195442534463170",
"156136969244990530431219627204875887987",
"289313048140665975705991099574537254387",
"5685128272666654397818596601519487550"
]
},
"id": "ASB-A-221855295-f1a102ef",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/ac1ccd49fe0e2b8f7de2e391d4f597ce56de53da",
"target": {
"file": "src/com/android/providers/media/util/FileUtils.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/ac1ccd49fe0e2b8f7de2e391d4f597ce56de53da"
],
"types": [
"EoP"
],
"spl": "2022-09-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"251272552318062483375803532600811265251",
"109158918448858443125635452458075127604",
"138587773904233750919147985483441127650",
"195309320759852002081564118618854052551",
"245237118464282618670486643864373561354",
"239923988918611491819555322259343837757",
"334522434390633449750374019879302161059",
"284145369461894307536698195442534463170",
"156136969244990530431219627204875887987",
"289313048140665975705991099574537254387",
"5685128272666654397818596601519487550"
]
},
"id": "ASB-A-221855295-06b0d5ac",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/18939f61c18602131116ac12eabaf5016f7b5180",
"target": {
"file": "src/com/android/providers/media/util/FileUtils.java"
}
},
{
"digest": {
"length": 269.0,
"function_hash": "149005686500020152072408424580414043116"
},
"id": "ASB-A-221855295-a1dd0b6b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/18939f61c18602131116ac12eabaf5016f7b5180",
"target": {
"function": "deleteIfAllowed",
"file": "src/com/android/providers/media/MediaProvider.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"83227273977673201952415963432411165056",
"240530743924061286780788861302376556044",
"6043250738476881819042753626898801111",
"35809543942109625896991360514551123473"
]
},
"id": "ASB-A-221855295-ba14e614",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/18939f61c18602131116ac12eabaf5016f7b5180",
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
}
},
{
"digest": {
"length": 1112.0,
"function_hash": "204881092998669550345217478148577572159"
},
"id": "ASB-A-221855295-e1a0f3c0",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/18939f61c18602131116ac12eabaf5016f7b5180",
"target": {
"function": "computeDataFromValues",
"file": "src/com/android/providers/media/util/FileUtils.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/18939f61c18602131116ac12eabaf5016f7b5180"
],
"types": [
"EoP"
],
"spl": "2022-09-01",
"severity": "High"
}