View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0001504 | K18X001.00 SKB SWAN | SW | public | 2022-06-30 18:29 | 2023-10-16 14:46 |
| Reporter | Assigned To | (ALTech) Wooshin Kang | Due Date | ||
| Priority | normal | Severity | s4-minor | Reproducibility | always |
| Status | closed | Resolution | won't fix | ||
| Summary | 0001504: [BTS] MBA_policy_violation-BFX-UA300 | ||||
| Description | Hi Wooshin, Recently, Google updated the BTS test suite. Our other customers have encountered MBA policy violation. so I built the latest code (2022/06/30) to check if AI SoundMax has this failure. Please check the attachment. You can ignore the warning "Vulnerable /system/app/PushAgent/PushAgent.apk", because this warning has already created https://jira.skbroadband.com/browse/BTVD-21408 (this warning will be treated as an alert on 2022-08-16) There are 2 deadline 2022-10-28 and 2022-09-28. Please check all apps in the attachment. I think you can ignore the following warning in attachment, the owner of these 3 apps are Foxconn and Synaptics. I'll check it later. MBA policy violation in /system/priv-app/SetupWizardCustomizer/SetupWizardCustomizer.apk (Foxconn) MBA policy violation in /system/priv-app/TvSettings/TvSettings.apk (Synaptics) MBA policy violation in /system/app/A2dpDeviceService/A2dpDeviceService.apk (Foxconn) Thanks, Jason | ||||
| Tags | No tags attached. | ||||
| Attach Tags | |||||
| User List |
(ALTech) Sangmin Choi , (SW) Jacky Chiang , (SW) Kerwin Chen |
|---|
|
2022-06-30 18:29 developer |
|
|
|
Hi Jason, Thanks for information, I will monitor it. thanks. |
|
|
Hi, Jason, The vendor who developed the PushAgent APK has fixed the BTS warning. Could you please run the BTS using following APK? The fixed APK was uploaded test branch named BFX-UA300_5.3.4_BTS_TEST. $ pwd vendor/skb/prebuilts/zinnaworks_push-agent $ git log -1 remotes/skb_prebuilts/BFX-UA300_5.3.4_BTS_TEST commit d78d5b6c0cde189efe40753de0c5f38cb00f6b65 (skb_prebuilts/BFX-UA300_5.3.4_BTS_TEST) Author: 양유식/디바이스개발스쿼드 <yusik.yang@sk.com> Date: Mon Jul 18 20:40:36 2022 +0900 [BPM-3983] Fix the vulnerability - Unsafe HostnameVerifier : Update PushAgent (50.43 - Morpheus Push Library 5.0.0.12) Thank you. |
|
|
Hi Sangmin, I've build the latest code with branch BFX-UA300_5.3.4_BTS_TEST. Please check the attachment (BTS-BFX-UA300-20220719.pdf) The following message is gone, The app com.skb.stbPush found at /system/app/PushAgent/PushAgent.apk is considered vulnerable because it contains an unsafe implementation of the interfaces HostnameVerifier or X509HostnameVerifier, which makes the app vulnerable to network attacks. Thanks, Jason |
|
|
Hi, Jason, Thank you. And, there is one more warning(CVE-2022-20223) which is not exist before, what is this warning? Did you expect it will be gone when the latest security patch is applied? |
|
|
Hi Sanmin, Regarding CVE-2022-20223, I am working on it. There is one 2022-07 Security patch in packages/apps/Settings Maybe Google forget to release the same modification in folder packages/apps/TvSettings. I've merged it to packages/apps/TvSettings manually by myself. I just submitted a test image for BTS and I think this warning (CVE-2022-20223) should go away after applying this modification. Thanks, Jason |
|
|
Hi Sanmin, I've fix the warning CVE-2022-20223, The number of warnings has been reduced from 23 to 22. Please check the attachment (19.534.15t2.jpg) |
|
|
Hi, Jason, Thank you. |
|
|
HI Jason, Did you get feedback from SOC ? If you have updates share please. Thanks. |
|
|
Hi Wooshin, I asked at least 2 Soc vendor last Friday, no update yet. There is an ATV bootcamp at the end of July, maybe their TAM is participating in it. I also asked the same question on Synaptics NEW jira, you can monitor the following link, https://synacsm.atlassian.net/servicedesk/customer/portal/173/CSMSKBSBLT-188 |
|
|
Hi All, According to ATV Summit 2022 (Certification section) MBA Policy are not currently enforced on TV. But it will eventually be enforced on TV. Thanks, Jason |
|
|
Hi Jason, Thanks for information. |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2022-06-30 18:29 |
|
New Issue | |
| 2022-06-30 18:29 |
|
Status | new => assigned |
| 2022-06-30 18:29 |
|
Assigned To | => (ALTech) Wooshin Kang |
| 2022-06-30 18:29 |
|
File Added: MBA_policy_violation-BFX-UA300.pdf | |
| 2022-06-30 19:34 | (ALTech) Wooshin Kang | Note Added: 0010283 | |
| 2022-07-01 08:30 |
|
Issue Monitored: (SW) Jacky Chiang | |
| 2022-07-01 08:30 |
|
Issue Monitored: (SW) Kerwin Chen | |
| 2022-07-06 12:18 | (ALTech) Sangmin Choi | Issue Monitored: (ALTech) Sangmin Choi | |
| 2022-07-19 09:59 | (ALTech) Sangmin Choi | Note Added: 0010406 | |
| 2022-07-19 14:10 |
|
Note Added: 0010415 | |
| 2022-07-19 14:10 |
|
File Added: BTS-BFX-UA300-20220719.pdf | |
| 2022-07-19 14:38 | (ALTech) Sangmin Choi | Note Added: 0010417 | |
| 2022-07-19 14:38 | (ALTech) Sangmin Choi | File Added: CVE-2022-20223.png | |
| 2022-07-19 15:15 |
|
Note Added: 0010419 | |
| 2022-07-19 15:16 |
|
Note Edited: 0010419 | |
| 2022-07-19 17:08 |
|
Note Added: 0010420 | |
| 2022-07-19 17:08 |
|
File Added: 19.534.15t2.jpg | |
| 2022-07-20 08:28 | (ALTech) Sangmin Choi | Note Added: 0010421 | |
| 2022-07-25 09:39 | (ALTech) Wooshin Kang | Note Added: 0010458 | |
| 2022-07-25 14:31 |
|
Note Added: 0010461 | |
| 2023-04-11 11:25 |
|
Note Added: 0012788 | |
| 2023-04-11 11:25 |
|
File Added: MBA_1.jpg | |
| 2023-04-11 11:25 |
|
File Added: MBA_2.jpg | |
| 2023-04-11 11:25 |
|
Status | assigned => resolved |
| 2023-04-11 11:25 |
|
Resolution | open => won't fix |
| 2023-04-11 12:56 | (ALTech) Wooshin Kang | Note Added: 0012791 | |
| 2023-04-11 13:40 |
|
Note Edited: 0012788 | |
| 2023-10-16 14:46 | (ALTech) Wooshin Kang | Status | resolved => closed |



