From 556a8529e6365de302796e2a36c4584ea5283180 Mon Sep 17 00:00:00 2001 From: Tad Date: Tue, 8 Sep 2020 17:02:41 -0400 Subject: [PATCH] Update AOSP CVE list to September patches - This will need to be re run after more links are added as usual --- Misc/Potentially_Missed_CVEs.txt | 1 + Misc/aosp-cves/cve_list-qc.txt | 2 +- Misc/aosp-cves/cve_list.txt | 4 +++- Misc/aosp-cves/gen_cve_list-qc.sh | 1 + Misc/aosp-cves/gen_cve_list.sh | 2 ++ 5 files changed, 8 insertions(+), 2 deletions(-) diff --git a/Misc/Potentially_Missed_CVEs.txt b/Misc/Potentially_Missed_CVEs.txt index 0d91ef54..910f41aa 100644 --- a/Misc/Potentially_Missed_CVEs.txt +++ b/Misc/Potentially_Missed_CVEs.txt @@ -7,5 +7,6 @@ CVE-2017-18275 CVE-2017-18276 CVE-2017-18278 CVE-2017-18279 +CVE-2019-5489 https://source.android.com/security/bulletin/pixel/2019-09-01 diff --git a/Misc/aosp-cves/cve_list-qc.txt b/Misc/aosp-cves/cve_list-qc.txt index 61cca0bb..f18e8a43 100644 --- a/Misc/aosp-cves/cve_list-qc.txt +++ b/Misc/aosp-cves/cve_list-qc.txt @@ -1,4 +1,4 @@ -#Last checked 2020/08/05 +#Last checked 2020/09/08 CVE-2015-0235 Link - https://source.codeaurora.org/quic/le//oe/recipes/commit/?id=6025569cb2a156bb6765dc14d66cb83f46a8c338 CVE-2015-3847 diff --git a/Misc/aosp-cves/cve_list.txt b/Misc/aosp-cves/cve_list.txt index d72aa8b2..5dd0334c 100644 --- a/Misc/aosp-cves/cve_list.txt +++ b/Misc/aosp-cves/cve_list.txt @@ -1,4 +1,4 @@ -#Last checked 2020/08/05 +#Last checked 2020/09/08 CVE-2014-9028 Link - external/flac - https://android.googlesource.com/platform/external/flac/+/fe03f73d86bb415f5d5145f0de091834d89ae3a9 Link - external/flac - https://android.googlesource.com/platform/external/flac/+/5859ae22db0a2d16af3e3ca19d582de37daf5eb6 @@ -1354,6 +1354,8 @@ CVE-2019-10509 Link - vendor/qcom-opensource/system/bt - https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/system/bt/commit/?id=9ac0f2da643d3830c2f5133392b42064031cd9b8 CVE-2019-10510 Link - vendor/qcom-opensource/system/bt - https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/system/bt/commit/?id=d005a97b4daa188a15696c46c72b67e5f49f7fc6 +CVE-2019-10521 + Link - https://source.codeaurora.org/quic/le/platform/hardware/qcom/gps/commit/?id=4788c8a1ee32619f59752d9068df2f5d316819eb CVE-2019-10569 Link - hardware/qcom/audio - https://source.codeaurora.org/quic/la/platform/hardware/qcom/audio/commit/?id=bbf4497352958dd27036503a43cd8a031e7eb9b1 CVE-2019-10581 diff --git a/Misc/aosp-cves/gen_cve_list-qc.sh b/Misc/aosp-cves/gen_cve_list-qc.sh index d34a598f..2e817e49 100644 --- a/Misc/aosp-cves/gen_cve_list-qc.sh +++ b/Misc/aosp-cves/gen_cve_list-qc.sh @@ -1,3 +1,4 @@ +java -jar $DOS_BINARY_PATCHER scraper "https://www.qualcomm.com/company/product-security/bulletins/september-2020-bulletin" >> cve_list-qc.txt java -jar $DOS_BINARY_PATCHER scraper "https://www.qualcomm.com/company/product-security/bulletins/august-2020-security-bulletin" >> cve_list-qc.txt java -jar $DOS_BINARY_PATCHER scraper "https://www.qualcomm.com/company/product-security/bulletins/july-2020-security-bulletin" >> cve_list-qc.txt java -jar $DOS_BINARY_PATCHER scraper "https://www.qualcomm.com/company/product-security/bulletins/june-2020-security-bulletin" >> cve_list-qc.txt diff --git a/Misc/aosp-cves/gen_cve_list.sh b/Misc/aosp-cves/gen_cve_list.sh index 9871509a..5eb408aa 100644 --- a/Misc/aosp-cves/gen_cve_list.sh +++ b/Misc/aosp-cves/gen_cve_list.sh @@ -1,3 +1,4 @@ +java -jar $DOS_BINARY_PATCHER scraper "https://source.android.com/security/bulletin/2020-09-01" >> cve_list.txt java -jar $DOS_BINARY_PATCHER scraper "https://source.android.com/security/bulletin/2020-08-01" >> cve_list.txt java -jar $DOS_BINARY_PATCHER scraper "https://source.android.com/security/bulletin/2020-07-01" >> cve_list.txt java -jar $DOS_BINARY_PATCHER scraper "https://source.android.com/security/bulletin/2020-06-01" >> cve_list.txt @@ -7,6 +8,7 @@ java -jar $DOS_BINARY_PATCHER scraper "https://source.android.com/security/bulle java -jar $DOS_BINARY_PATCHER scraper "https://source.android.com/security/bulletin/2020-02-01" >> cve_list.txt java -jar $DOS_BINARY_PATCHER scraper "https://source.android.com/security/bulletin/2020-01-01" >> cve_list.txt +java -jar $DOS_BINARY_PATCHER scraper "https://source.android.com/security/bulletin/pixel/2020-09-01" >> cve_list.txt java -jar $DOS_BINARY_PATCHER scraper "https://source.android.com/security/bulletin/pixel/2020-08-01" >> cve_list.txt java -jar $DOS_BINARY_PATCHER scraper "https://source.android.com/security/bulletin/pixel/2020-07-01" >> cve_list.txt java -jar $DOS_BINARY_PATCHER scraper "https://source.android.com/security/bulletin/pixel/2020-06-01" >> cve_list.txt