
CVE-2017-13286 Poc(non utilizzabile)
CVE-2017-13286 Poc(can not use)
Tutte le risorse provengono da questo articolo https://bbs.kanxue.com/thread-268506.htm
public void writeToParcel(Parcel dest, int flags) {
if (dest == null) {
throw new IllegalArgumentException("dest must not be null");
}
dest.writeInt(mRotation);
dest.writeInt(mSurfaceGroupId);
dest.writeInt(mSurfaceType);
dest.writeInt(mConfiguredSize.getWidth());
dest.writeInt(mConfiguredSize.getHeight());
dest.writeInt(mIsDeferredConfig ? 1 : 0);
dest.writeInt(mIsShared ? 1 : 0);
dest.writeTypedList(mSurfaces);
}
private OutputConfiguration(@NonNull Parcel source) {
int rotation = source.readInt();
int surfaceSetId = source.readInt();
int surfaceType = source.readInt();
int width = source.readInt();
int height = source.readInt();
boolean isDeferred = source.readInt() == 1;
// missing write mIsShared
ArrayList<Surface> surfaces = new ArrayList<Surface>();
source.readTypedList(surfaces, Surface.CREATOR);
checkArgumentInRange(rotation, ROTATION_0, ROTATION_270, "Rotation constant");
...
...
...
}
In questa versione di AOSP, mIsShared non viene letto, ma viene scritto
Sfruttando questo possiamo costruire dati di serializzazione Parcel maliziosi, facendo eseguire al sistema alcune azioni
Il codice vulnerabile si trova nella directory AOSP: frameworks/base/core/java/android/hardware/camera2/params/OutputConfiguration.java
Non solo è stato corretto, ma ora gli oggetti serializzati includono più elementi predefiniti