In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/a296a6520bef303faedbe8b4489f36e0e2b09d16",
"signature_version": "v1",
"deprecated": false,
"id": "ASB-A-294406604-50d17e5d",
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"57939264674174263502899728183470065665",
"156483739650783070040676283183882372427",
"43627227627199472868044543520274991244",
"165692613732677962069729788390091838178"
]
}
},
{
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/a296a6520bef303faedbe8b4489f36e0e2b09d16",
"signature_version": "v1",
"deprecated": false,
"id": "ASB-A-294406604-83ab504b",
"target": {
"function": "ensureFileColumns",
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Function",
"digest": {
"length": 9773.0,
"function_hash": "27241054463115702947468459533401732505"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/a296a6520bef303faedbe8b4489f36e0e2b09d16"
],
"types": [
"ID"
],
"severity": "High",
"spl": "2024-07-01"
}{
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"signature_version": "v1",
"deprecated": false,
"id": "ASB-A-294406604-ccb8d240",
"target": {
"function": "ensureFileColumns",
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Function",
"digest": {
"length": 9340.0,
"function_hash": "237362771053526941016576314456550928596"
}
},
{
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"signature_version": "v1",
"deprecated": false,
"id": "ASB-A-294406604-e2bc0314",
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"57939264674174263502899728183470065665",
"156483739650783070040676283183882372427",
"43627227627199472868044543520274991244",
"165692613732677962069729788390091838178"
]
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9"
],
"types": [
"ID"
],
"severity": "High",
"spl": "2024-07-01"
}{
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"signature_version": "v1",
"deprecated": false,
"id": "ASB-A-294406604-07c012ca",
"target": {
"function": "ensureFileColumns",
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Function",
"digest": {
"length": 9340.0,
"function_hash": "237362771053526941016576314456550928596"
}
},
{
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"signature_version": "v1",
"deprecated": false,
"id": "ASB-A-294406604-c7bbc338",
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"57939264674174263502899728183470065665",
"156483739650783070040676283183882372427",
"43627227627199472868044543520274991244",
"165692613732677962069729788390091838178"
]
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9"
],
"types": [
"ID"
],
"severity": "High",
"spl": "2024-07-01"
}{
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"signature_version": "v1",
"deprecated": false,
"id": "ASB-A-294406604-1cb6d073",
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"57939264674174263502899728183470065665",
"156483739650783070040676283183882372427",
"43627227627199472868044543520274991244",
"165692613732677962069729788390091838178"
]
}
},
{
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"signature_version": "v1",
"deprecated": false,
"id": "ASB-A-294406604-e4dd6d28",
"target": {
"function": "ensureFileColumns",
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Function",
"digest": {
"length": 9340.0,
"function_hash": "237362771053526941016576314456550928596"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9"
],
"types": [
"ID"
],
"severity": "High",
"spl": "2024-07-01"
}{
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"signature_version": "v1",
"deprecated": false,
"id": "ASB-A-294406604-3c2c9d39",
"target": {
"function": "ensureFileColumns",
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Function",
"digest": {
"length": 9340.0,
"function_hash": "237362771053526941016576314456550928596"
}
},
{
"source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9",
"signature_version": "v1",
"deprecated": false,
"id": "ASB-A-294406604-ac6450ee",
"target": {
"file": "src/com/android/providers/media/MediaProvider.java"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"57939264674174263502899728183470065665",
"156483739650783070040676283183882372427",
"43627227627199472868044543520274991244",
"165692613732677962069729788390091838178"
]
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/providers/MediaProvider/+/df39f8486b25473d0bdbeed896ad917e3c793bf9"
],
"types": [
"ID"
],
"severity": "High",
"spl": "2024-07-01"
}