In VideoFrame of VideoFrame.h, there is a possible abort due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"100148515362275207378196828111972919081",
"234827788084020004755170831494779627093",
"181446642267730195456455025267993066501",
"244612489925392101052323711752281219202",
"14030459318899937160932651170153437448",
"148164218045546464969198038657954231341"
]
},
"id": "PUB-A-233006499-4055d4c8",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/av/+/c5ecdd49bacda2b40d39771df59e1d2b598230a0",
"target": {
"file": "include/private/media/VideoFrame.h"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/av/+/c5ecdd49bacda2b40d39771df59e1d2b598230a0"
],
"types": [
"ID"
],
"spl": "2023-06-01",
"severity": "Moderate"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"100148515362275207378196828111972919081",
"234827788084020004755170831494779627093",
"181446642267730195456455025267993066501",
"244612489925392101052323711752281219202",
"14030459318899937160932651170153437448",
"148164218045546464969198038657954231341"
]
},
"id": "PUB-A-233006499-09ad0f19",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/av/+/014a9ed60d587b1b648e24a1f1d6873578e41758",
"target": {
"file": "include/private/media/VideoFrame.h"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/av/+/014a9ed60d587b1b648e24a1f1d6873578e41758"
],
"types": [
"ID"
],
"spl": "2023-06-01",
"severity": "Moderate"
}