In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/av/+/0efe2b4d6b739650039c2cab176ef11d5f5ac49c",
"target": {
"file": "media/libstagefright/rtsp/ARTPWriter.cpp"
},
"deprecated": false,
"id": "ASB-A-287298721-07f15a41",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"11263277234862368838928103238306349862",
"95926712572035257571059956409014047376",
"6785934054751617800003206332605034823",
"80935772684323423832167741694244018035"
]
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/av/+/0efe2b4d6b739650039c2cab176ef11d5f5ac49c"
],
"types": [
"EoP"
],
"severity": "High",
"spl": "2023-11-01"
}{
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/av/+/0efe2b4d6b739650039c2cab176ef11d5f5ac49c",
"target": {
"file": "media/libstagefright/rtsp/ARTPWriter.cpp"
},
"deprecated": false,
"id": "ASB-A-287298721-a1071b5f",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"11263277234862368838928103238306349862",
"95926712572035257571059956409014047376",
"6785934054751617800003206332605034823",
"80935772684323423832167741694244018035"
]
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/av/+/0efe2b4d6b739650039c2cab176ef11d5f5ac49c"
],
"types": [
"EoP"
],
"severity": "High",
"spl": "2023-11-01"
}{
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/av/+/0efe2b4d6b739650039c2cab176ef11d5f5ac49c",
"target": {
"file": "media/libstagefright/rtsp/ARTPWriter.cpp"
},
"deprecated": false,
"id": "ASB-A-287298721-0d291867",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"11263277234862368838928103238306349862",
"95926712572035257571059956409014047376",
"6785934054751617800003206332605034823",
"80935772684323423832167741694244018035"
]
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/av/+/0efe2b4d6b739650039c2cab176ef11d5f5ac49c"
],
"types": [
"EoP"
],
"severity": "High",
"spl": "2023-11-01"
}{
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/av/+/0efe2b4d6b739650039c2cab176ef11d5f5ac49c",
"target": {
"file": "media/libstagefright/rtsp/ARTPWriter.cpp"
},
"deprecated": false,
"id": "ASB-A-287298721-164f45e1",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"11263277234862368838928103238306349862",
"95926712572035257571059956409014047376",
"6785934054751617800003206332605034823",
"80935772684323423832167741694244018035"
]
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/av/+/0efe2b4d6b739650039c2cab176ef11d5f5ac49c"
],
"types": [
"EoP"
],
"severity": "High",
"spl": "2023-11-01"
}{
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/av/+/0efe2b4d6b739650039c2cab176ef11d5f5ac49c",
"target": {
"file": "media/libstagefright/rtsp/ARTPWriter.cpp"
},
"deprecated": false,
"id": "ASB-A-287298721-66430d15",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"11263277234862368838928103238306349862",
"95926712572035257571059956409014047376",
"6785934054751617800003206332605034823",
"80935772684323423832167741694244018035"
]
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/av/+/0efe2b4d6b739650039c2cab176ef11d5f5ac49c"
],
"types": [
"EoP"
],
"severity": "High",
"spl": "2023-11-01"
}