In parseSecurityParamsFromXml of XmlUtil.java, there is a possible bypass of user specified wifi encryption protocol due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"spl": "2023-06-01",
"severity": "Moderate",
"vanir_signatures": [
{
"deprecated": false,
"signature_version": "v1",
"id": "PUB-A-272755865-45fc285f",
"match_only_versions": [
"13-next"
],
"source": "https://android.googlesource.com/platform/packages/modules/Wifi/+/c2a9a9d11b4f26cb168517b15b1816016820406c",
"target": {
"file": "service/java/com/android/server/wifi/util/XmlUtil.java",
"function": "writeSecurityParamsListToXml"
},
"signature_type": "Function",
"digest": {
"function_hash": "80954735518544714308434795642535781605",
"length": 718.0
}
},
{
"deprecated": false,
"signature_version": "v1",
"id": "PUB-A-272755865-4b933f38",
"match_only_versions": [
"13-next"
],
"source": "https://android.googlesource.com/platform/packages/modules/Wifi/+/c2a9a9d11b4f26cb168517b15b1816016820406c",
"target": {
"file": "service/java/com/android/server/wifi/util/XmlUtil.java"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"257306786310735472085815403518200222659",
"82105747385047436454389612086911943351",
"66439885775036546881829881831165940913",
"5944828380836956629038202556971143829",
"3772508029498409403356350456980264630",
"264763154302323387921420235491045632235",
"315279082320211373729337702294532577749",
"276278887840455546535740095965425589176"
]
}
},
{
"deprecated": false,
"signature_version": "v1",
"id": "PUB-A-272755865-76e19e40",
"match_only_versions": [
"13-next"
],
"source": "https://android.googlesource.com/platform/packages/modules/Wifi/+/c2a9a9d11b4f26cb168517b15b1816016820406c",
"target": {
"file": "service/java/com/android/server/wifi/util/XmlUtil.java",
"function": "parseSecurityParamsFromXml"
},
"signature_type": "Function",
"digest": {
"function_hash": "114025694532549938339335102905705947951",
"length": 1001.0
}
}
],
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Wifi/+/c2a9a9d11b4f26cb168517b15b1816016820406c"
]
}
{
"spl": "2023-06-01",
"severity": "Moderate",
"vanir_signatures": [
{
"deprecated": false,
"signature_version": "v1",
"id": "PUB-A-272755865-8715a7b1",
"match_only_versions": [
"13"
],
"source": "https://android.googlesource.com/platform/packages/modules/Wifi/+/c2a9a9d11b4f26cb168517b15b1816016820406c",
"target": {
"file": "service/java/com/android/server/wifi/util/XmlUtil.java",
"function": "writeSecurityParamsListToXml"
},
"signature_type": "Function",
"digest": {
"function_hash": "80954735518544714308434795642535781605",
"length": 718.0
}
},
{
"deprecated": false,
"signature_version": "v1",
"id": "PUB-A-272755865-890958c5",
"match_only_versions": [
"13"
],
"source": "https://android.googlesource.com/platform/packages/modules/Wifi/+/c2a9a9d11b4f26cb168517b15b1816016820406c",
"target": {
"file": "service/java/com/android/server/wifi/util/XmlUtil.java"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"257306786310735472085815403518200222659",
"82105747385047436454389612086911943351",
"66439885775036546881829881831165940913",
"5944828380836956629038202556971143829",
"3772508029498409403356350456980264630",
"264763154302323387921420235491045632235",
"315279082320211373729337702294532577749",
"276278887840455546535740095965425589176"
]
}
},
{
"deprecated": false,
"signature_version": "v1",
"id": "PUB-A-272755865-fab06e13",
"match_only_versions": [
"13"
],
"source": "https://android.googlesource.com/platform/packages/modules/Wifi/+/c2a9a9d11b4f26cb168517b15b1816016820406c",
"target": {
"file": "service/java/com/android/server/wifi/util/XmlUtil.java",
"function": "parseSecurityParamsFromXml"
},
"signature_type": "Function",
"digest": {
"function_hash": "114025694532549938339335102905705947951",
"length": 1001.0
}
}
],
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Wifi/+/c2a9a9d11b4f26cb168517b15b1816016820406c"
]
}