In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"severity": "High",
"spl": "2023-03-01",
"vanir_signatures": [
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"158253382744967794372166426227829451328",
"208646129568712116042670616434092925745",
"267897132422978847766130599021982102399",
"89021460256006972424927287623588351745",
"257784892650917064621950304120855216852"
],
"threshold": 0.9
},
"id": "ASB-A-242299736-135dfe05",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/external/zlib/+/e754d32adb747041bdd27bd971d27fa6bc44108d",
"target": {
"file": "contrib/optimizations/inflate.c"
}
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"158253382744967794372166426227829451328",
"208646129568712116042670616434092925745",
"267897132422978847766130599021982102399",
"89021460256006972424927287623588351745",
"257784892650917064621950304120855216852"
],
"threshold": 0.9
},
"id": "ASB-A-242299736-e7e5790c",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/external/zlib/+/e754d32adb747041bdd27bd971d27fa6bc44108d",
"target": {
"file": "inflate.c"
}
}
],
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/external/zlib/+/e754d32adb747041bdd27bd971d27fa6bc44108d"
]
}{
"severity": "High",
"spl": "2023-03-01",
"vanir_signatures": [
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"158253382744967794372166426227829451328",
"208646129568712116042670616434092925745",
"267897132422978847766130599021982102399",
"89021460256006972424927287623588351745",
"257784892650917064621950304120855216852"
],
"threshold": 0.9
},
"id": "ASB-A-242299736-77f88dd7",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/external/zlib/+/1c4806afd7ae034aa9f86df35d4341a0b175a90a",
"target": {
"file": "contrib/optimizations/inflate.c"
}
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"158253382744967794372166426227829451328",
"208646129568712116042670616434092925745",
"267897132422978847766130599021982102399",
"89021460256006972424927287623588351745",
"257784892650917064621950304120855216852"
],
"threshold": 0.9
},
"id": "ASB-A-242299736-fd5674b1",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/external/zlib/+/1c4806afd7ae034aa9f86df35d4341a0b175a90a",
"target": {
"file": "inflate.c"
}
}
],
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/external/zlib/+/1c4806afd7ae034aa9f86df35d4341a0b175a90a"
]
}{
"severity": "High",
"spl": "2023-03-01",
"vanir_signatures": [
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"158253382744967794372166426227829451328",
"208646129568712116042670616434092925745",
"267897132422978847766130599021982102399",
"89021460256006972424927287623588351745",
"257784892650917064621950304120855216852"
],
"threshold": 0.9
},
"id": "ASB-A-242299736-48403612",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/external/zlib/+/172924248227e1da88a8e963c18dc6f38b725f7a",
"target": {
"file": "contrib/optimizations/inflate.c"
}
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"158253382744967794372166426227829451328",
"208646129568712116042670616434092925745",
"267897132422978847766130599021982102399",
"89021460256006972424927287623588351745",
"257784892650917064621950304120855216852"
],
"threshold": 0.9
},
"id": "ASB-A-242299736-96eb1dc5",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/external/zlib/+/172924248227e1da88a8e963c18dc6f38b725f7a",
"target": {
"file": "inflate.c"
}
}
],
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/external/zlib/+/172924248227e1da88a8e963c18dc6f38b725f7a"
]
}{
"severity": "High",
"spl": "2023-03-01",
"vanir_signatures": [
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"158253382744967794372166426227829451328",
"208646129568712116042670616434092925745",
"267897132422978847766130599021982102399",
"89021460256006972424927287623588351745",
"257784892650917064621950304120855216852"
],
"threshold": 0.9
},
"id": "ASB-A-242299736-65a7eba0",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/external/zlib/+/5abcd199d3375a20b650ce4b7f8a1bb84469cefd",
"target": {
"file": "inflate.c"
}
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"158253382744967794372166426227829451328",
"208646129568712116042670616434092925745",
"267897132422978847766130599021982102399",
"89021460256006972424927287623588351745",
"257784892650917064621950304120855216852"
],
"threshold": 0.9
},
"id": "ASB-A-242299736-84a433ec",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/external/zlib/+/5abcd199d3375a20b650ce4b7f8a1bb84469cefd",
"target": {
"file": "contrib/optimizations/inflate.c"
}
}
],
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/external/zlib/+/5abcd199d3375a20b650ce4b7f8a1bb84469cefd"
]
}{
"severity": "High",
"spl": "2023-03-01",
"vanir_signatures": [
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"158253382744967794372166426227829451328",
"208646129568712116042670616434092925745",
"267897132422978847766130599021982102399",
"89021460256006972424927287623588351745",
"257784892650917064621950304120855216852"
],
"threshold": 0.9
},
"id": "ASB-A-242299736-1bc72bde",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/external/zlib/+/e5a6e35a651c42d3a813e24af1000a3163da8a1b",
"target": {
"file": "contrib/optimizations/inflate.c"
}
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"158253382744967794372166426227829451328",
"208646129568712116042670616434092925745",
"267897132422978847766130599021982102399",
"89021460256006972424927287623588351745",
"257784892650917064621950304120855216852"
],
"threshold": 0.9
},
"id": "ASB-A-242299736-f1b644c5",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/external/zlib/+/e5a6e35a651c42d3a813e24af1000a3163da8a1b",
"target": {
"file": "inflate.c"
}
}
],
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/external/zlib/+/e5a6e35a651c42d3a813e24af1000a3163da8a1b"
]
}