Fix security vulnerability in DPMS#setProfileOwner
Fail with a more general error message if the provided component is not installed, this avoids exploiting the API to identify which packages are installed without holding QUERY_ALL_PACKAGES Test: Manual testing Bug: 184658476 Change-Id: I47b80acb4c847f3bc0c6550deca40b192f57d598
This commit is contained in:
@@ -8552,11 +8552,12 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
|
||||
synchronized (getLockObject()) {
|
||||
enforceCanSetProfileOwnerLocked(
|
||||
caller, who, userHandle, hasIncompatibleAccountsOrNonAdb);
|
||||
Preconditions.checkArgument(isPackageInstalledForUser(who.getPackageName(), userHandle),
|
||||
"Component " + who + " not installed for userId:" + userHandle);
|
||||
final ActiveAdmin admin = getActiveAdminUncheckedLocked(who, userHandle);
|
||||
Preconditions.checkArgument(admin != null && !getUserData(
|
||||
userHandle).mRemovingAdmins.contains(who), "Not active admin: " + who);
|
||||
Preconditions.checkArgument(
|
||||
isPackageInstalledForUser(who.getPackageName(), userHandle)
|
||||
&& admin != null
|
||||
&& !getUserData(userHandle).mRemovingAdmins.contains(who),
|
||||
"Not active admin: " + who);
|
||||
|
||||
final int parentUserId = getProfileParentId(userHandle);
|
||||
// When trying to set a profile owner on a new user, it may be that this user is
|
||||
|
||||
Reference in New Issue
Block a user