In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"spl": "2024-07-01",
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"57939264674174263502899728183470065665",
"156483739650783070040676283183882372427",
"43627227627199472868044543520274991244",
"165692613732677962069729788390091838178"
]
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/a296a6520bef303faedbe8b4489f36e0e2b09d16",
"id": "ASB-A-294406604-50d17e5d",
"deprecated": false,
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"digest": {
"function_hash": "27241054463115702947468459533401732505",
"length": 9773.0
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/a296a6520bef303faedbe8b4489f36e0e2b09d16",
"id": "ASB-A-294406604-83ab504b",
"deprecated": false,
"target": {
"file": "src/com/android/providers/media/MediaProvider.java",
"function": "ensureFileColumns"
},
"signature_type": "Function",
"signature_version": "v1"
}
],
"types": [
"ID"
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/a296a6520bef303faedbe8b4489f36e0e2b09d16"
],
"severity": "High"
}{
"spl": "2024-07-01",
"vanir_signatures": [
{
"digest": {
"function_hash": "237362771053526941016576314456550928596",
"length": 9340.0
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"id": "ASB-A-294406604-ccb8d240",
"deprecated": false,
"target": {
"file": "src/com/android/providers/media/MediaProvider.java",
"function": "ensureFileColumns"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"57939264674174263502899728183470065665",
"156483739650783070040676283183882372427",
"43627227627199472868044543520274991244",
"165692613732677962069729788390091838178"
]
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"id": "ASB-A-294406604-e2bc0314",
"deprecated": false,
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Line",
"signature_version": "v1"
}
],
"types": [
"ID"
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9"
],
"severity": "High"
}{
"spl": "2024-07-01",
"vanir_signatures": [
{
"digest": {
"function_hash": "237362771053526941016576314456550928596",
"length": 9340.0
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"id": "ASB-A-294406604-07c012ca",
"deprecated": false,
"target": {
"file": "src/com/android/providers/media/MediaProvider.java",
"function": "ensureFileColumns"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"57939264674174263502899728183470065665",
"156483739650783070040676283183882372427",
"43627227627199472868044543520274991244",
"165692613732677962069729788390091838178"
]
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"id": "ASB-A-294406604-c7bbc338",
"deprecated": false,
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Line",
"signature_version": "v1"
}
],
"types": [
"ID"
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9"
],
"severity": "High"
}{
"spl": "2024-07-01",
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"57939264674174263502899728183470065665",
"156483739650783070040676283183882372427",
"43627227627199472868044543520274991244",
"165692613732677962069729788390091838178"
]
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"id": "ASB-A-294406604-1cb6d073",
"deprecated": false,
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"digest": {
"function_hash": "237362771053526941016576314456550928596",
"length": 9340.0
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"id": "ASB-A-294406604-e4dd6d28",
"deprecated": false,
"target": {
"file": "src/com/android/providers/media/MediaProvider.java",
"function": "ensureFileColumns"
},
"signature_type": "Function",
"signature_version": "v1"
}
],
"types": [
"ID"
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9"
],
"severity": "High"
}{
"spl": "2024-07-01",
"vanir_signatures": [
{
"digest": {
"function_hash": "237362771053526941016576314456550928596",
"length": 9340.0
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"id": "ASB-A-294406604-3c2c9d39",
"deprecated": false,
"target": {
"file": "src/com/android/providers/media/MediaProvider.java",
"function": "ensureFileColumns"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"57939264674174263502899728183470065665",
"156483739650783070040676283183882372427",
"43627227627199472868044543520274991244",
"165692613732677962069729788390091838178"
]
},
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"id": "ASB-A-294406604-ac6450ee",
"deprecated": false,
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Line",
"signature_version": "v1"
}
],
"types": [
"ID"
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9"
],
"severity": "High"
}