Fix vulnerability in LockSettings service am: 2d71384a13
am: 485fbda04c
Change-Id: I07def32199ecdbbb32aa6ecaca20724cfc81265c
This commit is contained in:
@@ -296,7 +296,7 @@ public class LockPatternUtils {
|
||||
return false;
|
||||
}
|
||||
} catch (RemoteException re) {
|
||||
return true;
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -345,7 +345,7 @@ public class LockPatternUtils {
|
||||
return false;
|
||||
}
|
||||
} catch (RemoteException re) {
|
||||
return true;
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -523,6 +523,9 @@ public class LockSettingsService extends ILockSettings.Stub {
|
||||
private VerifyCredentialResponse doVerifyPattern(String pattern, boolean hasChallenge,
|
||||
long challenge, int userId) throws RemoteException {
|
||||
checkPasswordReadPermission(userId);
|
||||
if (TextUtils.isEmpty(pattern)) {
|
||||
throw new IllegalArgumentException("Pattern can't be null or empty");
|
||||
}
|
||||
CredentialHash storedHash = mStorage.readPatternHash(userId);
|
||||
boolean shouldReEnrollBaseZero = storedHash != null && storedHash.isBaseZeroPattern;
|
||||
|
||||
@@ -579,6 +582,9 @@ public class LockSettingsService extends ILockSettings.Stub {
|
||||
private VerifyCredentialResponse doVerifyPassword(String password, boolean hasChallenge,
|
||||
long challenge, int userId) throws RemoteException {
|
||||
checkPasswordReadPermission(userId);
|
||||
if (TextUtils.isEmpty(password)) {
|
||||
throw new IllegalArgumentException("Password can't be null or empty");
|
||||
}
|
||||
CredentialHash storedHash = mStorage.readPasswordHash(userId);
|
||||
return verifyCredential(userId, storedHash, password, hasChallenge, challenge,
|
||||
new CredentialUtil() {
|
||||
|
||||
Reference in New Issue
Block a user