In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"225322178506426539697111397787662797815",
"203007418245486663436757567325339439945",
"283734241504781186210317179610985584230",
"275702062095050616325682778445507309860"
]
},
"id": "ASB-A-230493653-6e99e429",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/av/+/9d33304ec75b366ed9750e7bde6f96f8c704e1c8",
"target": {
"file": "media/extractors/mp4/MPEG4Extractor.cpp"
}
},
{
"digest": {
"length": 7552.0,
"function_hash": "60777411702810882278554162367025679691"
},
"id": "ASB-A-230493653-e652dde0",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/av/+/9d33304ec75b366ed9750e7bde6f96f8c704e1c8",
"target": {
"function": "MPEG4Extractor::updateAudioTrackInfoFromESDS_MPEG4Audio",
"file": "media/extractors/mp4/MPEG4Extractor.cpp"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/av/+/9d33304ec75b366ed9750e7bde6f96f8c704e1c8"
],
"types": [
"ID"
],
"spl": "2022-08-01",
"severity": "High"
}
{
"vanir_signatures": [
{
"digest": {
"length": 7552.0,
"function_hash": "60777411702810882278554162367025679691"
},
"id": "ASB-A-230493653-019db7bc",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/av/+/9d33304ec75b366ed9750e7bde6f96f8c704e1c8",
"target": {
"function": "MPEG4Extractor::updateAudioTrackInfoFromESDS_MPEG4Audio",
"file": "media/extractors/mp4/MPEG4Extractor.cpp"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"225322178506426539697111397787662797815",
"203007418245486663436757567325339439945",
"283734241504781186210317179610985584230",
"275702062095050616325682778445507309860"
]
},
"id": "ASB-A-230493653-776cb4cf",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/av/+/9d33304ec75b366ed9750e7bde6f96f8c704e1c8",
"target": {
"file": "media/extractors/mp4/MPEG4Extractor.cpp"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/av/+/9d33304ec75b366ed9750e7bde6f96f8c704e1c8"
],
"types": [
"ID"
],
"spl": "2022-08-01",
"severity": "High"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"225322178506426539697111397787662797815",
"203007418245486663436757567325339439945",
"283734241504781186210317179610985584230",
"275702062095050616325682778445507309860"
]
},
"id": "ASB-A-230493653-a0dfe305",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/av/+/9d33304ec75b366ed9750e7bde6f96f8c704e1c8",
"target": {
"file": "media/extractors/mp4/MPEG4Extractor.cpp"
}
},
{
"digest": {
"length": 7552.0,
"function_hash": "60777411702810882278554162367025679691"
},
"id": "ASB-A-230493653-bdcec08c",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/av/+/9d33304ec75b366ed9750e7bde6f96f8c704e1c8",
"target": {
"function": "MPEG4Extractor::updateAudioTrackInfoFromESDS_MPEG4Audio",
"file": "media/extractors/mp4/MPEG4Extractor.cpp"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/av/+/9d33304ec75b366ed9750e7bde6f96f8c704e1c8"
],
"types": [
"ID"
],
"spl": "2022-08-01",
"severity": "High"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"225322178506426539697111397787662797815",
"203007418245486663436757567325339439945",
"283734241504781186210317179610985584230",
"275702062095050616325682778445507309860"
]
},
"id": "ASB-A-230493653-938171ed",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/av/+/9d33304ec75b366ed9750e7bde6f96f8c704e1c8",
"target": {
"file": "media/extractors/mp4/MPEG4Extractor.cpp"
}
},
{
"digest": {
"length": 7552.0,
"function_hash": "60777411702810882278554162367025679691"
},
"id": "ASB-A-230493653-ac083058",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/av/+/9d33304ec75b366ed9750e7bde6f96f8c704e1c8",
"target": {
"function": "MPEG4Extractor::updateAudioTrackInfoFromESDS_MPEG4Audio",
"file": "media/extractors/mp4/MPEG4Extractor.cpp"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/av/+/9d33304ec75b366ed9750e7bde6f96f8c704e1c8"
],
"types": [
"ID"
],
"spl": "2022-08-01",
"severity": "High"
}