In bindSelection of DatabaseUtils.java, there is a possible way to access files from other applications due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/b5aadde5f1d3c47562eade2223f7a30729dda53e"
],
"spl": "2023-09-01",
"severity": "High",
"types": [
"ID"
],
"vanir_signatures": [
{
"target": {
"file": "src/com/android/providers/media/util/DatabaseUtils.java"
},
"signature_type": "Line",
"signature_version": "v1",
"id": "ASB-A-223793631-c648b5ee",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"29589661527729970920197757447098681201",
"227676290786395735151124985128560214970",
"279969880971284412529864377845756430800",
"133626510894911829191706094865819018408",
"110616539877835788141470216616498105401",
"88965750662070752662688070633701222223",
"276245187349861928585160787886810289883"
]
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/b5aadde5f1d3c47562eade2223f7a30729dda53e"
},
{
"target": {
"file": "src/com/android/providers/media/util/DatabaseUtils.java",
"function": "bindSelection"
},
"signature_type": "Function",
"signature_version": "v1",
"id": "ASB-A-223793631-f49d6e6d",
"deprecated": false,
"digest": {
"length": 1576.0,
"function_hash": "167780436427771854248856327374794323637"
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/b5aadde5f1d3c47562eade2223f7a30729dda53e"
}
]
}{
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/8f07a4f7941c53d96e097c3c840e2f4bc0814b2c"
],
"spl": "2023-09-01",
"severity": "High",
"types": [
"ID"
],
"vanir_signatures": [
{
"target": {
"file": "src/com/android/providers/media/util/DatabaseUtils.java"
},
"signature_type": "Line",
"signature_version": "v1",
"id": "ASB-A-223793631-00b545ee",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"29589661527729970920197757447098681201",
"227676290786395735151124985128560214970",
"279969880971284412529864377845756430800",
"133626510894911829191706094865819018408",
"110616539877835788141470216616498105401",
"88965750662070752662688070633701222223",
"276245187349861928585160787886810289883"
]
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/8f07a4f7941c53d96e097c3c840e2f4bc0814b2c"
},
{
"target": {
"file": "src/com/android/providers/media/util/DatabaseUtils.java",
"function": "bindSelection"
},
"signature_type": "Function",
"signature_version": "v1",
"id": "ASB-A-223793631-d097bf3d",
"deprecated": false,
"digest": {
"length": 1576.0,
"function_hash": "167780436427771854248856327374794323637"
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/8f07a4f7941c53d96e097c3c840e2f4bc0814b2c"
}
]
}{
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/a48b01f78f28fc642b144c673bfcd12ae78c5a73"
],
"spl": "2023-09-01",
"severity": "High",
"types": [
"ID"
],
"vanir_signatures": [
{
"target": {
"file": "src/com/android/providers/media/util/DatabaseUtils.java",
"function": "bindSelection"
},
"signature_type": "Function",
"signature_version": "v1",
"id": "ASB-A-223793631-52d56f81",
"deprecated": false,
"digest": {
"length": 1576.0,
"function_hash": "167780436427771854248856327374794323637"
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/a48b01f78f28fc642b144c673bfcd12ae78c5a73"
},
{
"target": {
"file": "src/com/android/providers/media/util/DatabaseUtils.java"
},
"signature_type": "Line",
"signature_version": "v1",
"id": "ASB-A-223793631-907778a5",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"29589661527729970920197757447098681201",
"227676290786395735151124985128560214970",
"279969880971284412529864377845756430800",
"133626510894911829191706094865819018408",
"110616539877835788141470216616498105401",
"88965750662070752662688070633701222223",
"276245187349861928585160787886810289883"
]
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/a48b01f78f28fc642b144c673bfcd12ae78c5a73"
}
]
}