
CVE-2017-13286 Poc (उपयोग नहीं किया जा सकता)
CVE-2017-13286 Poc(उपयोग नहीं किया जा सकता)
सभी संसाधन इस लेख से लिए गए हैं https://bbs.kanxue.com/thread-268506.htm
public void writeToParcel(Parcel dest, int flags) {
if (dest == null) {
throw new IllegalArgumentException("dest must not be null");
}
dest.writeInt(mRotation);
dest.writeInt(mSurfaceGroupId);
dest.writeInt(mSurfaceType);
dest.writeInt(mConfiguredSize.getWidth());
dest.writeInt(mConfiguredSize.getHeight());
dest.writeInt(mIsDeferredConfig ? 1 : 0);
dest.writeInt(mIsShared ? 1 : 0);
dest.writeTypedList(mSurfaces);
}
private OutputConfiguration(@NonNull Parcel source) {
int rotation = source.readInt();
int surfaceSetId = source.readInt();
int surfaceType = source.readInt();
int width = source.readInt();
int height = source.readInt();
boolean isDeferred = source.readInt() == 1;
// missing write mIsShared
ArrayList<Surface> surfaces = new ArrayList<Surface>();
source.readTypedList(surfaces, Surface.CREATOR);
checkArgumentInRange(rotation, ROTATION_0, ROTATION_270, "Rotation constant");
...
...
...
}
जैसा कि देखा जा सकता है, AOSP के इस संस्करण में mIsShared पढ़ा नहीं गया, लेकिन लिखा गया
इसका उपयोग करके हम दुर्भावनापूर्ण parcel सीरियलाइज़ेशन डेटा तैयार कर सकते हैं, जिससे सिस्टम कुछ कार्य कर सके
भेद्यता कोड AOSP में इस निर्देशिका में है: frameworks/base/core/java/android/hardware/camera2/params/OutputConfiguration.java
यह न केवल ठीक कर दिया गया है, बल्कि वर्तमान सीरियलाइज़ेशन ऑब्जेक्ट में और अधिक डिफ़ॉल्ट तत्व जोड़े गए हैं