<feed xmlns='http://www.w3.org/2005/Atom'>
<title>packages_apps_Contacts, branch cm-13.0</title>
<subtitle>Unnamed repository; edit this file 'description' to name the repository.
</subtitle>
<link rel='alternate' type='text/html' href='https://git.replicant.us/replicant/packages_apps_Contacts/'/>
<entry>
<title>Automatic translation import</title>
<updated>2019-08-10T18:49:40+00:00</updated>
<author>
<name>Michael Bestas</name>
<email>mkbestas@lineageos.org</email>
</author>
<published>2019-08-10T18:49:40+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/replicant/packages_apps_Contacts/commit/?id=a02c818f59957f7bba3ce31faf8b4fff16062db9'/>
<id>a02c818f59957f7bba3ce31faf8b4fff16062db9</id>
<content type='text'>
Change-Id: Ifc51521870c294101a6b6e8810d2ce6ace95a334
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: Ifc51521870c294101a6b6e8810d2ce6ace95a334
</pre>
</div>
</content>
</entry>
<entry>
<title>Patch URI vulnerability in contact photo editing</title>
<updated>2019-02-02T20:51:31+00:00</updated>
<author>
<name>Gary Mai</name>
<email>garymai@google.com</email>
</author>
<published>2018-09-05T22:17:41+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/replicant/packages_apps_Contacts/commit/?id=52851972282d45af9514a8c46e226216292a9b5d'/>
<id>52851972282d45af9514a8c46e226216292a9b5d</id>
<content type='text'>
Don't allow reading of "file://" URIs that don't point to "/storage" during the
photo saving flow.

This is to prevent malicious apps from asking us to read our own private
files which we copy into a temporary "content://" URI that we give to a
cropping app (with permission to read).

Fixing here patches both PhotoSelectionHandler.java and
AttachPhotoActivity.java.

Tested:
Manual with the fake gallery app. Confirmed that selecting an "image"
with a URI of our own shared_pref file fails without reading it.
ContactPhotoUtilsTest

Bug: 113597344
Change-Id: Iabb4f8139cedb7d7b865d69a4b95a4997f64c71d
(cherry picked from commit ccfd94b965c1e9c2e0b239c12137c239c602070d)
CVE-2018-9587
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Don't allow reading of "file://" URIs that don't point to "/storage" during the
photo saving flow.

This is to prevent malicious apps from asking us to read our own private
files which we copy into a temporary "content://" URI that we give to a
cropping app (with permission to read).

Fixing here patches both PhotoSelectionHandler.java and
AttachPhotoActivity.java.

Tested:
Manual with the fake gallery app. Confirmed that selecting an "image"
with a URI of our own shared_pref file fails without reading it.
ContactPhotoUtilsTest

Bug: 113597344
Change-Id: Iabb4f8139cedb7d7b865d69a4b95a4997f64c71d
(cherry picked from commit ccfd94b965c1e9c2e0b239c12137c239c602070d)
CVE-2018-9587
</pre>
</div>
</content>
</entry>
<entry>
<title>Automatic translation import</title>
<updated>2017-12-14T02:58:19+00:00</updated>
<author>
<name>Abhisek Devkota</name>
<email>ciwrl@lineageos.org</email>
</author>
<published>2017-12-14T02:58:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/replicant/packages_apps_Contacts/commit/?id=6a2c65b96c508637e3326dfefd33e8ec287052a2'/>
<id>6a2c65b96c508637e3326dfefd33e8ec287052a2</id>
<content type='text'>
Change-Id: I1f980b9c7a575db3cf58ded8a1f29e0c10ee74be
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: I1f980b9c7a575db3cf58ded8a1f29e0c10ee74be
</pre>
</div>
</content>
</entry>
<entry>
<title>Automatic translation import</title>
<updated>2017-09-20T00:16:07+00:00</updated>
<author>
<name>Abhisek Devkota</name>
<email>ciwrl@lineageos.org</email>
</author>
<published>2017-09-20T00:16:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/replicant/packages_apps_Contacts/commit/?id=375f0f461fb35da65bbbc84e32c46ebc2921f256'/>
<id>375f0f461fb35da65bbbc84e32c46ebc2921f256</id>
<content type='text'>
Change-Id: I5455288646819b4e539d98ab09445deffcdf5877
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: I5455288646819b4e539d98ab09445deffcdf5877
</pre>
</div>
</content>
</entry>
<entry>
<title>Automatic translation import</title>
<updated>2017-07-28T04:20:57+00:00</updated>
<author>
<name>Abhisek Devkota</name>
<email>ciwrl@lineageos.org</email>
</author>
<published>2017-07-28T04:20:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/replicant/packages_apps_Contacts/commit/?id=3e5d2dc583ace5b4f1f66f3a3915757ca751b1f3'/>
<id>3e5d2dc583ace5b4f1f66f3a3915757ca751b1f3</id>
<content type='text'>
Change-Id: I42d90ff892b2a2a04c6650441b36e704b39c72a8
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: I42d90ff892b2a2a04c6650441b36e704b39c72a8
</pre>
</div>
</content>
</entry>
<entry>
<title>Automatic translation import</title>
<updated>2017-07-04T03:42:06+00:00</updated>
<author>
<name>Abhisek Devkota</name>
<email>ciwrl@lineageos.org</email>
</author>
<published>2017-07-04T03:42:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/replicant/packages_apps_Contacts/commit/?id=93507dec66b01af5ffe5f79aeef9de8eb0488a44'/>
<id>93507dec66b01af5ffe5f79aeef9de8eb0488a44</id>
<content type='text'>
Change-Id: I4f4995313643c30be86e7180d9cb89bed4b4276f
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: I4f4995313643c30be86e7180d9cb89bed4b4276f
</pre>
</div>
</content>
</entry>
<entry>
<title>Automatic translation import</title>
<updated>2017-06-23T05:40:40+00:00</updated>
<author>
<name>Abhisek Devkota</name>
<email>ciwrl@lineageos.org</email>
</author>
<published>2017-06-23T05:40:40+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/replicant/packages_apps_Contacts/commit/?id=ac7f94d8074b485aa414d7af333d7c14fc778c12'/>
<id>ac7f94d8074b485aa414d7af333d7c14fc778c12</id>
<content type='text'>
Change-Id: I2167cab9b35149f7fc2b1f6581de427c910ede78
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: I2167cab9b35149f7fc2b1f6581de427c910ede78
</pre>
</div>
</content>
</entry>
<entry>
<title>Automatic translation import</title>
<updated>2017-06-04T01:42:34+00:00</updated>
<author>
<name>Abhisek Devkota</name>
<email>ciwrl@lineageos.org</email>
</author>
<published>2017-06-04T01:42:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/replicant/packages_apps_Contacts/commit/?id=f471b06d64bcade27a87a2e5b266c5c6a72327c0'/>
<id>f471b06d64bcade27a87a2e5b266c5c6a72327c0</id>
<content type='text'>
Change-Id: Iec2ecc09a3242d6e06abb4cd5b69c0a01c19403c
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: Iec2ecc09a3242d6e06abb4cd5b69c0a01c19403c
</pre>
</div>
</content>
</entry>
<entry>
<title>Automatic translation import</title>
<updated>2017-04-28T21:27:37+00:00</updated>
<author>
<name>Abhisek Devkota</name>
<email>ciwrl@lineageos.org</email>
</author>
<published>2017-04-28T21:27:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/replicant/packages_apps_Contacts/commit/?id=76cc0f38cf9c4fd9bce3222dfb5aa665160876d9'/>
<id>76cc0f38cf9c4fd9bce3222dfb5aa665160876d9</id>
<content type='text'>
Change-Id: I5ca8ef0d4afbad8b30ef9c576632c30956d1ecb5
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: I5ca8ef0d4afbad8b30ef9c576632c30956d1ecb5
</pre>
</div>
</content>
</entry>
<entry>
<title>Automatic translation import</title>
<updated>2017-02-20T00:52:17+00:00</updated>
<author>
<name>Abhisek Devkota</name>
<email>ciwrl@lineageos.org</email>
</author>
<published>2017-02-20T00:52:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/replicant/packages_apps_Contacts/commit/?id=979a31b60e34b66189ad6783f70e61bf0b527aa8'/>
<id>979a31b60e34b66189ad6783f70e61bf0b527aa8</id>
<content type='text'>
Change-Id: I418361a27359f83e7a818fa64881394c2d4a9a2f
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: I418361a27359f83e7a818fa64881394c2d4a9a2f
</pre>
</div>
</content>
</entry>
</feed>
