In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "281253907639525144025299373930782407033", "132876137314617094737140570055861165390", "4690526999091256758990293462794369238", "7544939645273274879206324847218671046", "12071255814901493088040976794853679443", "164998211426005178073519557115678279380", "224677706242864877018902563102024141642", "33215650706164921697314748434731617263", "123209350887477386788433845434072400276", "9931110887952007559812108128041600154", "214728215846428908470951434899761443372", "278832171060732843206969616038814260467" ] }, "id": "ASB-A-264880895-bf5e2d80", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java" }, "signature_type": "Line" }, { "digest": { "length": 2447.0, "function_hash": "157104286834053058667808334963109926916" }, "id": "ASB-A-264880895-cac8316b", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java", "function": "update" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c" ], "spl": "2023-08-01", "severity": "High", "types": [ "DoS" ] }
{ "vanir_signatures": [ { "digest": { "length": 2447.0, "function_hash": "157104286834053058667808334963109926916" }, "id": "ASB-A-264880895-49dfd506", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java", "function": "update" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "281253907639525144025299373930782407033", "132876137314617094737140570055861165390", "4690526999091256758990293462794369238", "7544939645273274879206324847218671046", "12071255814901493088040976794853679443", "164998211426005178073519557115678279380", "224677706242864877018902563102024141642", "33215650706164921697314748434731617263", "123209350887477386788433845434072400276", "9931110887952007559812108128041600154", "214728215846428908470951434899761443372", "278832171060732843206969616038814260467" ] }, "id": "ASB-A-264880895-82485d3b", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c" ], "spl": "2023-08-01", "severity": "High", "types": [ "DoS" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "281253907639525144025299373930782407033", "132876137314617094737140570055861165390", "4690526999091256758990293462794369238", "7544939645273274879206324847218671046", "12071255814901493088040976794853679443", "164998211426005178073519557115678279380", "224677706242864877018902563102024141642", "33215650706164921697314748434731617263", "123209350887477386788433845434072400276", "9931110887952007559812108128041600154", "214728215846428908470951434899761443372", "278832171060732843206969616038814260467" ] }, "id": "ASB-A-264880895-2621a41e", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java" }, "signature_type": "Line" }, { "digest": { "length": 2447.0, "function_hash": "157104286834053058667808334963109926916" }, "id": "ASB-A-264880895-82a3ce1d", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java", "function": "update" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c" ], "spl": "2023-08-01", "severity": "High", "types": [ "DoS" ] }
{ "vanir_signatures": [ { "digest": { "length": 2447.0, "function_hash": "157104286834053058667808334963109926916" }, "id": "ASB-A-264880895-05e0fc8a", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java", "function": "update" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "281253907639525144025299373930782407033", "132876137314617094737140570055861165390", "4690526999091256758990293462794369238", "7544939645273274879206324847218671046", "12071255814901493088040976794853679443", "164998211426005178073519557115678279380", "224677706242864877018902563102024141642", "33215650706164921697314748434731617263", "123209350887477386788433845434072400276", "9931110887952007559812108128041600154", "214728215846428908470951434899761443372", "278832171060732843206969616038814260467" ] }, "id": "ASB-A-264880895-763b8eb0", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c" ], "spl": "2023-08-01", "severity": "High", "types": [ "DoS" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "281253907639525144025299373930782407033", "132876137314617094737140570055861165390", "4690526999091256758990293462794369238", "7544939645273274879206324847218671046", "12071255814901493088040976794853679443", "164998211426005178073519557115678279380", "224677706242864877018902563102024141642", "33215650706164921697314748434731617263", "123209350887477386788433845434072400276", "9931110887952007559812108128041600154", "214728215846428908470951434899761443372", "278832171060732843206969616038814260467" ] }, "id": "ASB-A-264880895-2eb35e48", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java" }, "signature_type": "Line" }, { "digest": { "length": 2447.0, "function_hash": "157104286834053058667808334963109926916" }, "id": "ASB-A-264880895-ba1c5e2d", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java", "function": "update" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c" ], "spl": "2023-08-01", "severity": "High", "types": [ "DoS" ] }