In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
{
"types": [
"ID"
],
"severity": "Moderate",
"fixes": [
"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/561e28af0c3baf6c25c42f7383411bee79139f41"
],
"spl": "2022-12-01",
"vanir_signatures": [
{
"id": "PUB-A-224770203-4a67ded2",
"signature_version": "v1",
"match_only_versions": [
"13"
],
"source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/561e28af0c3baf6c25c42f7383411bee79139f41",
"deprecated": false,
"target": {
"file": "src/com/android/providers/telephony/MmsSmsProvider.java"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"175278434493877219041305268878872093326",
"27272561965854949146123458815165972263",
"223552482003786354991201828198178774298",
"87875702481257780381372651189034741421",
"27398525298253817439086317880426186214",
"247097726139767068152210776798215643129",
"42973832947563651813844174996399787973",
"243705358534627401397731811153310912311",
"190521588167200224755839801483910998614",
"38947201479845264073759646330827678555"
]
},
"signature_type": "Line"
},
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/561e28af0c3baf6c25c42f7383411bee79139f41",
"deprecated": false,
"target": {
"file": "src/com/android/providers/telephony/MmsSmsProvider.java",
"function": "query"
},
"id": "PUB-A-224770203-a06dfb12",
"digest": {
"function_hash": "24073405600031326241509208613221419142",
"length": 5084.0
},
"signature_type": "Function"
}
]
}