VBRISeeker::CreateFromSource() may cause an uncaught c++ exception due to trying to allocate a buffer where the size is attacker controllable.
Fix: https://android.googlesource.com/platform/frameworks/av/+/453b351ac5bd2b6619925dc966da60adf6b3126c
PoC: https://github.com/derrekr/android_security/blob/master/CVE-2017-0392/vbri_test.mp3
暂无评论