ASB-A-224314979

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-224314979.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-224314979
Aliases
Published
2022-06-01T00:00:00Z
Modified
2026-04-28T15:17:37.552933Z
Summary
[none]
Details

In transportDecOutOfBandConfig of tpdeclib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android
platform/external/aac

Package

Name
platform/external/aac

Affected ranges

Type
ECOSYSTEM
Events
Introduced
12L-next:0
Fixed
12L-next:2022-06-01

Affected versions

Other
12L-next

Ecosystem specific

{
    "spl": "2022-06-01",
    "fixes": [
        "https://android.googlesource.com/platform/external/aac/+/067929dcd3467fd8e1383303efaff2cfc37224e9"
    ],
    "types": [
        "RCE"
    ],
    "vanir_signatures": [
        {
            "signature_type": "Function",
            "signature_version": "v1",
            "deprecated": false,
            "digest": {
                "length": 2284.0,
                "function_hash": "14688623539237930573622344493800917118"
            },
            "source": "https://android.googlesource.com/platform/external/aac/+/067929dcd3467fd8e1383303efaff2cfc37224e9",
            "target": {
                "function": "transportDec_OutOfBandConfig",
                "file": "libMpegTPDec/src/tpdec_lib.cpp"
            },
            "id": "ASB-A-224314979-45959e09"
        },
        {
            "signature_type": "Line",
            "signature_version": "v1",
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "41834245073546748005348337198116649443",
                    "296567283181987654677179610525862122783",
                    "108587633537507210242609878158511307392",
                    "263040339922716737265934089119049662491",
                    "13461143593537092071846640702810093743"
                ],
                "threshold": 0.9
            },
            "source": "https://android.googlesource.com/platform/external/aac/+/067929dcd3467fd8e1383303efaff2cfc37224e9",
            "target": {
                "file": "libMpegTPDec/src/tpdec_lib.cpp"
            },
            "id": "ASB-A-224314979-885abf8a"
        }
    ],
    "severity": "Critical"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-224314979.json"
platform/external/aac

Package

Name
platform/external/aac

Affected ranges

Type
ECOSYSTEM
Events
Introduced
10:0
Fixed
10:2022-06-01

Affected versions

Other
10

Ecosystem specific

{
    "spl": "2022-06-01",
    "fixes": [
        "https://android.googlesource.com/platform/external/aac/+/eb07c22519d94e573f2a02947094acd2219dc07a"
    ],
    "types": [
        "RCE"
    ],
    "vanir_signatures": [
        {
            "signature_type": "Function",
            "signature_version": "v1",
            "deprecated": false,
            "digest": {
                "length": 2284.0,
                "function_hash": "14688623539237930573622344493800917118"
            },
            "source": "https://android.googlesource.com/platform/external/aac/+/eb07c22519d94e573f2a02947094acd2219dc07a",
            "target": {
                "function": "transportDec_OutOfBandConfig",
                "file": "libMpegTPDec/src/tpdec_lib.cpp"
            },
            "id": "ASB-A-224314979-15504185"
        },
        {
            "signature_type": "Line",
            "signature_version": "v1",
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "41834245073546748005348337198116649443",
                    "296567283181987654677179610525862122783",
                    "108587633537507210242609878158511307392",
                    "263040339922716737265934089119049662491",
                    "13461143593537092071846640702810093743"
                ],
                "threshold": 0.9
            },
            "source": "https://android.googlesource.com/platform/external/aac/+/eb07c22519d94e573f2a02947094acd2219dc07a",
            "target": {
                "file": "libMpegTPDec/src/tpdec_lib.cpp"
            },
            "id": "ASB-A-224314979-faefdf1e"
        }
    ],
    "severity": "Critical"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-224314979.json"
platform/external/aac

Package

Name
platform/external/aac

Affected ranges

Type
ECOSYSTEM
Events
Introduced
11:0
Fixed
11:2022-06-01

Affected versions

Other
11

Ecosystem specific

{
    "spl": "2022-06-01",
    "fixes": [
        "https://android.googlesource.com/platform/external/aac/+/6a3817573b089f01b13f4f3a195dda8a345d8fe0"
    ],
    "types": [
        "RCE"
    ],
    "vanir_signatures": [
        {
            "signature_type": "Line",
            "signature_version": "v1",
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "41834245073546748005348337198116649443",
                    "296567283181987654677179610525862122783",
                    "108587633537507210242609878158511307392",
                    "263040339922716737265934089119049662491",
                    "13461143593537092071846640702810093743"
                ],
                "threshold": 0.9
            },
            "source": "https://android.googlesource.com/platform/external/aac/+/6a3817573b089f01b13f4f3a195dda8a345d8fe0",
            "target": {
                "file": "libMpegTPDec/src/tpdec_lib.cpp"
            },
            "id": "ASB-A-224314979-096f7809"
        },
        {
            "signature_type": "Function",
            "signature_version": "v1",
            "deprecated": false,
            "digest": {
                "length": 2284.0,
                "function_hash": "14688623539237930573622344493800917118"
            },
            "source": "https://android.googlesource.com/platform/external/aac/+/6a3817573b089f01b13f4f3a195dda8a345d8fe0",
            "target": {
                "function": "transportDec_OutOfBandConfig",
                "file": "libMpegTPDec/src/tpdec_lib.cpp"
            },
            "id": "ASB-A-224314979-4a17c1c2"
        }
    ],
    "severity": "Critical"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-224314979.json"
platform/external/aac

Package

Name
platform/external/aac

Affected ranges

Type
ECOSYSTEM
Events
Introduced
12:0
Fixed
12:2022-06-01

Affected versions

Other
12

Ecosystem specific

{
    "spl": "2022-06-01",
    "fixes": [
        "https://android.googlesource.com/platform/external/aac/+/23ef1ac38c2dae4cd755880fc8f98491efd26027"
    ],
    "types": [
        "RCE"
    ],
    "vanir_signatures": [
        {
            "signature_type": "Function",
            "signature_version": "v1",
            "deprecated": false,
            "digest": {
                "length": 2284.0,
                "function_hash": "14688623539237930573622344493800917118"
            },
            "source": "https://android.googlesource.com/platform/external/aac/+/23ef1ac38c2dae4cd755880fc8f98491efd26027",
            "target": {
                "function": "transportDec_OutOfBandConfig",
                "file": "libMpegTPDec/src/tpdec_lib.cpp"
            },
            "id": "ASB-A-224314979-22721a4c"
        },
        {
            "signature_type": "Line",
            "signature_version": "v1",
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "41834245073546748005348337198116649443",
                    "296567283181987654677179610525862122783",
                    "108587633537507210242609878158511307392",
                    "263040339922716737265934089119049662491",
                    "13461143593537092071846640702810093743"
                ],
                "threshold": 0.9
            },
            "source": "https://android.googlesource.com/platform/external/aac/+/23ef1ac38c2dae4cd755880fc8f98491efd26027",
            "target": {
                "file": "libMpegTPDec/src/tpdec_lib.cpp"
            },
            "id": "ASB-A-224314979-fb38480f"
        }
    ],
    "severity": "Critical"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-224314979.json"
platform/external/aac

Package

Name
platform/external/aac

Affected ranges

Type
ECOSYSTEM
Events
Introduced
12L:0
Fixed
12L:2022-06-01

Affected versions

Other
12L

Ecosystem specific

{
    "spl": "2022-06-01",
    "fixes": [
        "https://android.googlesource.com/platform/external/aac/+/2768a078f34a4d6cdb05916ad0e1f02d4c73fb6b"
    ],
    "types": [
        "RCE"
    ],
    "vanir_signatures": [
        {
            "signature_type": "Line",
            "signature_version": "v1",
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "41834245073546748005348337198116649443",
                    "296567283181987654677179610525862122783",
                    "108587633537507210242609878158511307392",
                    "263040339922716737265934089119049662491",
                    "13461143593537092071846640702810093743"
                ],
                "threshold": 0.9
            },
            "source": "https://android.googlesource.com/platform/external/aac/+/2768a078f34a4d6cdb05916ad0e1f02d4c73fb6b",
            "target": {
                "file": "libMpegTPDec/src/tpdec_lib.cpp"
            },
            "id": "ASB-A-224314979-12997a9a"
        },
        {
            "signature_type": "Function",
            "signature_version": "v1",
            "deprecated": false,
            "digest": {
                "length": 2284.0,
                "function_hash": "14688623539237930573622344493800917118"
            },
            "source": "https://android.googlesource.com/platform/external/aac/+/2768a078f34a4d6cdb05916ad0e1f02d4c73fb6b",
            "target": {
                "function": "transportDec_OutOfBandConfig",
                "file": "libMpegTPDec/src/tpdec_lib.cpp"
            },
            "id": "ASB-A-224314979-9cdb4d92"
        }
    ],
    "severity": "Critical"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-224314979.json"