ASB-A-221041256
Dashboard / Vulnerabilities / ASB-A-221041256
Summary:
Details: In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References: https://source.android.com/security/bulletin/2022-08-01, https://android.googlesource.com/platform/packages/apps/Settings/+/a9da6b809944018ef4c1a8eaecdec9cdecf47e15, https://android.googlesource.com/platform/packages/apps/Settings/+/1de10d24aa8d6a54b991299091877b18ee696d73, https://android.googlesource.com/platform/packages/apps/Settings/+/9bd1402e5aa758f2843154f395b5a5dfa91c1dca, https://android.googlesource.com/platform/packages/apps/Settings/+/e4c22580c9a66a3d5523782c2daa707531210227, https://android.googlesource.com/platform/packages/apps/Settings/+/ec3ae8bb178b8b5fb54572632e77984f9bfd5b86, https://android.googlesource.com/platform/packages/apps/Settings/+/40fbcf333f09a92d6499cf94d67c60c3a03c9a33
Affected packages
Package
Name: platform/packages/apps/Settings
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
