{"id":"PUB-A-224769956","details":"In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-224769956","CVE-2022-20517"],"modified":"2026-05-29T15:55:33.750044621Z","published":"2022-12-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2022-12-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6d3d099d902a3c258972e46e4bc033f46b73109f"}],"affected":[{"package":{"name":"platform/packages/providers/TelephonyProvider","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2022-12-01"}]}],"versions":["13"],"ecosystem_specific":{"vanir_signatures":[{"deprecated":false,"target":{"file":"src/com/android/providers/telephony/MmsSmsProvider.java","function":"getMessagesByPhoneNumber"},"signature_version":"v1","id":"PUB-A-224769956-33afdf62","match_only_versions":["13"],"digest":{"length":1407,"function_hash":"22422532387122491668667721950104656157"},"source":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6d3d099d902a3c258972e46e4bc033f46b73109f","signature_type":"Function"},{"deprecated":false,"target":{"file":"src/com/android/providers/telephony/MmsSmsProvider.java"},"signature_version":"v1","id":"PUB-A-224769956-63b4c4c4","match_only_versions":["13"],"digest":{"threshold":0.9,"line_hashes":["258934897897631415745520717000714098069","197014184272332667846658434605393915898","246664981731303886033131157814483634983","101001494901914073283465168712290708531","40781936514460825829631966867885287527","74775515332393555247263924237908194486","71228892074586123301732053782579261311","105011803168551978084127322986875381163","137265764517892057556664940942374249360","96700296200703501421605498402110971047","204863617846661698942456037915140423870","252949432377023224110765175983327207907","277647244589725688428892329248863886364","306605336572531699012372318475898263443","169838437779391581360466352827228668039","316756949732311853477928376052124049665","76444377936777127146241846239546812827","12758008060783028391415423680115144311","151384020286346887885906492235622483531"]},"source":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6d3d099d902a3c258972e46e4bc033f46b73109f","signature_type":"Line"}],"spl":"2022-12-01","types":["ID"],"fixes":["https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6d3d099d902a3c258972e46e4bc033f46b73109f"],"severity":"Moderate"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/PUB-A-224769956.json"}}],"schema_version":"1.7.5"}