summaryrefslogtreecommitdiffstats
path: root/res/values-zh-rHK/cm_strings.xml
diff options
context:
space:
mode:
authorRaman Tenneti <rtenneti@google.com>2018-11-27 13:47:04 -0800
committerTim Schumacher <timschumi@gmx.de>2019-03-23 15:58:36 +0100
commit2e6af7773dd792199efda5d47c470ec554edb291 (patch)
treeca0330a2a42ae2d86c5fae5403166d007e17a739 /res/values-zh-rHK/cm_strings.xml
parent91b8abdada31e816ecc02163a14718117b402c76 (diff)
downloadandroid_packages_apps_Email-2e6af7773dd792199efda5d47c470ec554edb291.tar.gz
android_packages_apps_Email-2e6af7773dd792199efda5d47c470ec554edb291.tar.bz2
android_packages_apps_Email-2e6af7773dd792199efda5d47c470ec554edb291.zip
AOSP/Email - Second part of the Security Vulnerability fix -
Email App: Malicious app is able to compose message with hidden attachments and bypass attachments path checks attaching private files from /data/data/com.android.email/* + Ported the following CLs. Code is different from gmail. Made the changes to work with Email. ++ https://critique.corp.google.com/#review/136780360 +++ Differentiating our Compose intents from other app's intent. Added ComposeActivityEmailExternal method and it always returns true. Treat body and quoted text as plaintext if intent is external. Bug: 32068883 Bug: 32502421 Bug: 32589229 Test: manual - Ran the following tests on Pixel phone. Tested the Email UI. $ adb install -r out/target/product/marlin/system/app/Email/Email.apk $ adb install -r app-debug.apk Success $ adb shell am start -n com.test.poc.poc32589229/.MainActivity -a android.intent.action.MAIN Starting: Intent { act=android.intent.action.MAIN cmp=com.test.poc.poc32589229/.MainActivity } Duplicated the steps in https://b.corp.google.com/issues/32589229#comment5 and didn't get the attachments after the fix (was getting attachments before the fix). $ adb install -r out/target/product/marlin/testcases/EmailTests/EmailTests.apk Performing Streamed Install Success $ adb shell am instrument -w com.android.email.tests The number of failures are same as before (with or without this change). Tests run: 158, Failures: 5 Change-Id: I4eda17af7f60e1c92f49ffa6025b328f6481ec76 (cherry picked from commit c87d04b8c190f52c4f7e8a22dfaa2b5e065415fe)
Diffstat (limited to 'res/values-zh-rHK/cm_strings.xml')
0 files changed, 0 insertions, 0 deletions