Age | Commit message (Collapse) | Author |
|
am: 0f1787b8e4 -s ours am: e33dde450b -s ours am: 57aa11328a am: e411343c31 am: fe28569bf2 -s ours am: fb09c27ba3 am: b5d75c8af5 am: 8da5eddeb6 am: 956a850170 -s ours am: 42f2549716 am: 2c678233d3
am: 7b509c2890
Change-Id: Idc8c20d79d6c17eed8d299b1336dc58fbb5d6496
|
|
am: 0f1787b8e4 -s ours am: e33dde450b -s ours am: 57aa11328a am: e411343c31 am: fe28569bf2 -s ours am: fb09c27ba3 am: b5d75c8af5 am: 8da5eddeb6 am: 956a850170 -s ours am: 42f2549716
am: 2c678233d3
Change-Id: I9492da0fd8f2c12571e9a183e6491de5c2f46c3f
|
|
am: 0f1787b8e4 -s ours am: e33dde450b -s ours am: 57aa11328a am: e411343c31 am: fe28569bf2 -s ours am: fb09c27ba3 am: b5d75c8af5 am: 8da5eddeb6 am: 956a850170 -s ours
am: 42f2549716
Change-Id: I682ce21861160ffdeeeeb914968b2a1c31f725e8
|
|
am: 0f1787b8e4 -s ours am: e33dde450b -s ours am: 57aa11328a am: e411343c31 am: fe28569bf2 -s ours am: fb09c27ba3 am: b5d75c8af5 am: 8da5eddeb6
am: 956a850170 -s ours
Change-Id: Ibffa5650d7ee57c4df19824efdfccbfd9ef4045d
|
|
am: 0f1787b8e4 -s ours am: e33dde450b -s ours am: 57aa11328a am: e411343c31 am: fe28569bf2 -s ours am: fb09c27ba3 am: b5d75c8af5
am: 8da5eddeb6
Change-Id: I6be321778f32e13e823ba244f59ee071ae358878
|
|
am: 0f1787b8e4 -s ours am: e33dde450b -s ours am: 57aa11328a am: e411343c31 am: fe28569bf2 -s ours am: fb09c27ba3
am: b5d75c8af5
Change-Id: I946158738844b48866e9d5e4f17cd17ab2bf9f70
|
|
am: 0f1787b8e4 -s ours am: e33dde450b -s ours am: 57aa11328a am: e411343c31 am: fe28569bf2 -s ours
am: fb09c27ba3
Change-Id: Iddbf33a00472c8d6eb9992befd4efbda873d0c8a
|
|
am: 0f1787b8e4 -s ours am: e33dde450b -s ours am: 57aa11328a am: e411343c31
am: fe28569bf2 -s ours
Change-Id: I3773c0168b520ce1bb61ddccadff2fc4f2804ed2
|
|
am: 0f1787b8e4 -s ours am: e33dde450b -s ours am: 57aa11328a
am: e411343c31
Change-Id: I39d20b12cfdef8a6faefe3e1c943300402cbe3d3
|
|
am: 0f1787b8e4 -s ours am: e33dde450b -s ours
am: 57aa11328a
Change-Id: Ie81690e2de660eec58512d1a43ffd52fedbca827
|
|
am: 0f1787b8e4 -s ours
am: e33dde450b -s ours
Change-Id: I2da37316922f306cc9f2156016f6a62a43acb569
|
|
am: 0f1787b8e4 -s ours
Change-Id: Id5097ae2be27a6ade1b67469292538bffd616ca5
|
|
am: 87be55a2c5
Change-Id: Id7a231bc6408ce29b3ce6e623cfd1deb6ce05adf
|
|
am: 4d43d4ae1c
Change-Id: I5d4203b5b5239d1c5a4f2715a343be3f01a7e339
|
|
9b35eea4c5 am: 093c608106 am: c7ba2c9c4e am: a2c9fbde45 am: 4b0afdab56 am: 244074273b am: 2a40e91775 am: 9f9c17637c
am: 77c0c25126
Change-Id: I99b543f5e926b80b0562aa2d63ce5dc06dc33c52
|
|
9b35eea4c5 am: 093c608106 am: c7ba2c9c4e am: a2c9fbde45 am: 4b0afdab56 am: 244074273b am: 2a40e91775
am: 9f9c17637c
Change-Id: I756ba62e388f4f71f00a21ba3fb673d584de9563
|
|
9b35eea4c5 am: 093c608106 am: c7ba2c9c4e am: a2c9fbde45 am: 4b0afdab56 am: 244074273b
am: 2a40e91775
Change-Id: If5fd6f49691d2709b5ed89faa1d564c27b1f9091
|
|
9b35eea4c5 am: 093c608106 am: c7ba2c9c4e am: a2c9fbde45 am: 4b0afdab56
am: 244074273b
Change-Id: I70ff67e29992b44596364a5aa426cd8acbd0b403
|
|
9b35eea4c5 am: 093c608106 am: c7ba2c9c4e am: a2c9fbde45
am: 4b0afdab56
Change-Id: I993285ade7ed21785eee9e27eaa37bab81221b5b
|
|
9b35eea4c5 am: 093c608106 am: c7ba2c9c4e
am: a2c9fbde45
Change-Id: Ida56bd49be857709ddfecb8cf142ddc386f6d3cc
|
|
9b35eea4c5 am: 093c608106
am: c7ba2c9c4e
Change-Id: I1954ff3a746c01d32283780af76dcc336a5d93fa
|
|
am: 093c608106
Change-Id: Ic321d4743d90e27d41c3fe736a3c87cb286b8eb4
|
|
am: 9b35eea4c5
Change-Id: Ia3ba22bf28426aa589231168a8ee24a35cf4ce49
|
|
am: 4fc61f9a45
Change-Id: I95587b5a4bba8c6bc7d78e94e3a033f5e6bf04c2
|
|
am: 9794d7e821
Change-Id: I6817a364fdadedb7edbab7901770a62986510971
|
|
The security issue occurs because id is allowed to be an arbitrary
path instead of being limited to what it is -- a long. Both id
and account id are now parsed into longs (and if either fails, an
error will be logged and null will be returned).
Tested/verified error is logged using the reported attack.
BUG=30745403
Change-Id: Ia21418545bbaeb96fb5ab6c3f4e71858e57b8684
|
|
The security issue occurs because id is allowed to be an arbitrary
path instead of being limited to what it is -- a long. Both id
and account id are now parsed into longs (and if either fails, an
error will be logged and null will be returned).
Tested/verified error is logged using the reported attack.
BUG=30745403
Change-Id: Ibe87479fd798da7da0e8809e37a39a4dfc708658
|
|
91910ffe05 am: ef2d5c6cd2 am: 93c84ad4df am: a7416672bd am: d1cb6efd81 am: a7a7326e76 am: 94336ac061 am: 6c0ca15fee am: c679726d87
am: 8b3dc05e75
Change-Id: I61b233f0371dfce6c66168e1acf56d7c136a2aa1
|
|
91910ffe05 am: ef2d5c6cd2 am: 93c84ad4df am: a7416672bd am: d1cb6efd81 am: a7a7326e76 am: 94336ac061 am: 6c0ca15fee
am: c679726d87
Change-Id: Ic489a34cfa4ce84e1dd745e3bdd5d746c7793cc3
|
|
91910ffe05 am: ef2d5c6cd2 am: 93c84ad4df am: a7416672bd am: d1cb6efd81 am: a7a7326e76 am: 94336ac061
am: 6c0ca15fee
Change-Id: I1f3c9ff74297e1b82b7456e10c76011497469944
|
|
91910ffe05 am: ef2d5c6cd2 am: 93c84ad4df am: a7416672bd am: d1cb6efd81 am: a7a7326e76
am: 94336ac061
Change-Id: I8d136b400b45fefeff6a163eb054ec686c2fb4b8
|
|
91910ffe05 am: ef2d5c6cd2 am: 93c84ad4df am: a7416672bd am: d1cb6efd81
am: a7a7326e76
Change-Id: Ib65489cb279ed05bd9afb39eae5a0e807527dc8e
|
|
91910ffe05 am: ef2d5c6cd2 am: 93c84ad4df am: a7416672bd
am: d1cb6efd81
Change-Id: I9fe608f3ad418600d4377cd7217136be61e087cb
|
|
91910ffe05 am: ef2d5c6cd2 am: 93c84ad4df
am: a7416672bd
Change-Id: Ic3ac0d9e6d1b73f1b8148a02adc7ba0b438ee552
|
|
91910ffe05 am: ef2d5c6cd2
am: 93c84ad4df
Change-Id: I3aa4582a276996d4ae67b782d18fbdbea6e66621
|
|
91910ffe05
am: ef2d5c6cd2
Change-Id: Iaeee610351f0a69be2cd2151456e9a8146288d50
|
|
am: 91910ffe05
Change-Id: I6b3ea655946eb97b2355203c45723f9259982064
|
|
am: a7d6dc37b2
Change-Id: I0da830e43f0c5cbfd1337d3ab429f620e0e971d0
|
|
am: a17c6c6ddd
Change-Id: I313229042d2ddaa24537f3a6e02b13d2da015fe1
|
|
Bug: 29767043
Change-Id: Ib9f16385a5e63557b6f293d148e49c9ad044c9b4
|
|
EmailProvider. am: 4cd6044 am: 59cac70 am: cfa3cee am: b2f6959 am: 76d3280 am: 1a7a329 am: 2e3f2aa
am: ebd7fc4
* commit 'ebd7fc4a574de71f00ee49f56b78a41fd87402fd':
Don't allow cachedFile Attachments if the content Uri is pointing to EmailProvider.
|
|
EmailProvider. am: 4cd6044 am: 59cac70 am: cfa3cee am: b2f6959 am: 76d3280 am: 1a7a329
am: 2e3f2aa
* commit '2e3f2aa116851382f612d51d7803164466eb7a35':
Don't allow cachedFile Attachments if the content Uri is pointing to EmailProvider.
|
|
EmailProvider. am: 4cd6044 am: 59cac70 am: cfa3cee am: b2f6959 am: 76d3280
am: 1a7a329
* commit '1a7a3291d695ee41c5ff5af303c3d580d7542c9d':
Don't allow cachedFile Attachments if the content Uri is pointing to EmailProvider.
|
|
EmailProvider. am: 4cd6044 am: 59cac70 am: cfa3cee am: b2f6959
am: 76d3280
* commit '76d32800486998942295218ddc89bdbd01c7df43':
Don't allow cachedFile Attachments if the content Uri is pointing to EmailProvider.
|
|
EmailProvider. am: 4cd6044 am: 59cac70 am: cfa3cee
am: b2f6959
* commit 'b2f69593ec1e523067dc693396832c1848c578c2':
Don't allow cachedFile Attachments if the content Uri is pointing to EmailProvider.
|
|
EmailProvider. am: 4cd6044 am: 59cac70
am: cfa3cee
* commit 'cfa3cee8247ed49bc176bab5a80376c623025a88':
Don't allow cachedFile Attachments if the content Uri is pointing to EmailProvider.
|
|
EmailProvider. am: 4cd6044
am: 59cac70
* commit '59cac7084266925f3c8970af2d98d40f3d1f9473':
Don't allow cachedFile Attachments if the content Uri is pointing to EmailProvider.
|
|
EmailProvider.
am: 4cd6044
* commit '4cd604447745e25c4aa486fd7cc463595db21cd7':
Don't allow cachedFile Attachments if the content Uri is pointing to EmailProvider.
|
|
EmailProvider.
This is to backport a security fix reported by b/27308057 and b/27335139.
Also, add Analytics for these errors.
Bug: b/27335139
Change-Id: Iaacb34e4983cdf9a85487222ae930cb64d80a193
|
|
translations. DO NOT MERGE
* commit '3b152dec578b0484c979de779c3d32f62562fa6f':
|