In bindSelection of DatabaseUtils.java, there is a possible way to access files from other applications due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "29589661527729970920197757447098681201", "227676290786395735151124985128560214970", "279969880971284412529864377845756430800", "133626510894911829191706094865819018408", "110616539877835788141470216616498105401", "88965750662070752662688070633701222223", "276245187349861928585160787886810289883" ] }, "id": "ASB-A-223793631-c648b5ee", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/b5aadde5f1d3c47562eade2223f7a30729dda53e", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/util/DatabaseUtils.java" }, "signature_type": "Line" }, { "digest": { "length": 1576.0, "function_hash": "167780436427771854248856327374794323637" }, "id": "ASB-A-223793631-f49d6e6d", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/b5aadde5f1d3c47562eade2223f7a30729dda53e", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/util/DatabaseUtils.java", "function": "bindSelection" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/b5aadde5f1d3c47562eade2223f7a30729dda53e" ], "spl": "2023-09-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "29589661527729970920197757447098681201", "227676290786395735151124985128560214970", "279969880971284412529864377845756430800", "133626510894911829191706094865819018408", "110616539877835788141470216616498105401", "88965750662070752662688070633701222223", "276245187349861928585160787886810289883" ] }, "id": "ASB-A-223793631-00b545ee", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/8f07a4f7941c53d96e097c3c840e2f4bc0814b2c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/util/DatabaseUtils.java" }, "signature_type": "Line" }, { "digest": { "length": 1576.0, "function_hash": "167780436427771854248856327374794323637" }, "id": "ASB-A-223793631-d097bf3d", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/8f07a4f7941c53d96e097c3c840e2f4bc0814b2c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/util/DatabaseUtils.java", "function": "bindSelection" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/8f07a4f7941c53d96e097c3c840e2f4bc0814b2c" ], "spl": "2023-09-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "digest": { "length": 1576.0, "function_hash": "167780436427771854248856327374794323637" }, "id": "ASB-A-223793631-52d56f81", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/a48b01f78f28fc642b144c673bfcd12ae78c5a73", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/util/DatabaseUtils.java", "function": "bindSelection" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "29589661527729970920197757447098681201", "227676290786395735151124985128560214970", "279969880971284412529864377845756430800", "133626510894911829191706094865819018408", "110616539877835788141470216616498105401", "88965750662070752662688070633701222223", "276245187349861928585160787886810289883" ] }, "id": "ASB-A-223793631-907778a5", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/a48b01f78f28fc642b144c673bfcd12ae78c5a73", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/util/DatabaseUtils.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/a48b01f78f28fc642b144c673bfcd12ae78c5a73" ], "spl": "2023-09-01", "severity": "High", "types": [ "ID" ] }