Jump to content

SonicStage CP 4.3 contains playlist security hole

Rate this topic


SteveLoh

Recommended Posts

According to Engadget (http://www.engadget.com/2007/10/31/sonys-sonicstage-cp-contains-playlist-security-hole/) SonicStage CP 4.3 contains playlist security hole !

"The bug is triggered by .m3u playlists that contain over 1000 characters and there are already sample exploits floating around, so those of you still rocking the ATRAC action may want to avoid downloaded playlists until things get patched up."

Edited by SteveLoh
Link to comment
Share on other sites

This was already raised here.

At times I wish that site would do some research. The error relates to a m3u playlist that contains a file name over 1000 characters. Read the advice from the link in this paragraph it gives more professional advice.

I would like to add avoid downloading m3u file you plan to import into SonicStage. If you need to then CHECK the m3u playlist by editing it using a text editor for long filenames. Deleting the line(s) that contain the entry will resolve the issue.

I do not how serious this BUG is in a real world situation, but I do not know if anyone uses m3u file.

Link to comment
Share on other sites

The fact it's a classed as Highly Critical,

http://secunia.com/advisories/27270/

Means that Sony can't afford to waste time releasing an update to fix this. I will be emailing them this afternoon, to try and find out if an new SonicStage is forthcoming..

A software security company did some research and was able to discover a bug in SonicStage that can be exploited. The problem relates to how SonicStage parses the m3u file. Only a software patch is needed to be released, which should be coming. It could be only one line of code. Imagine Microsoft or Apple releasing completely new version of their software of bugs in their software. If you do not use m3u files I would not worry about it, or avoid m3u files from unsure sources.

Link to comment
Share on other sites

  • 2 weeks later...

There is some update (Version 4.3.01.14280) - full installer without drivers, released 11/20/2007, on the VAIO ftp site: ftp://ftp.vaio-link.com/pub/DOWNLOADS/SO/...01198207-UN.EXE. I am not sure what it does, since the files inside do not seem to be updated at all.

I think the old 4.3 drivers will still work: ftp://ftp.vaio-link.com/pub/DNA/VISTA/MD/PA_DRIVER.EXE.

Edited by Avrin
Link to comment
Share on other sites

There is some update (Version 4.3.01.14280) - full installer without drivers, released 11/20/2007, on the VAIO ftp site: ftp://ftp.vaio-link.com/pub/DOWNLOADS/SO/...01198207-UN.EXE. I am not sure what it does, since the files inside do not seem to be updated at all.

I think the old 4.3 drivers will still work: ftp://ftp.vaio-link.com/pub/DNA/VISTA/MD/PA_DRIVER.EXE.

Working well here, with my NW-A3000.

SonicStage : 4.3.01.14050

SonicStage Add-on for 4.3 Upgrade : 4.3.01.14050

OpenMG Secure Module : 4.7.00.12140

MagicGate Memory Stick Device : 4.7.00.12140

NW-E2, NW-E3, NW-E5 and NW-E8P : 4.7.00.12140

OpenMG CD : 4.7.00.12140

M.S. PRO : 4.7.00.12140

CD Walkman : 4.7.00.12140

ATRAC Audio Device with Intelligent function : 4.7.00.12140

Hi-MD : 4.7.00.12140

Music Clip, NW-S4, NW-E7 and NW-E10 : 4.7.00.12140

ATRAC Audio Device : 4.7.00.12140

Net MD : 4.7.00.12140

EMD Plug-in: 4.3.01.14020

CD-R Writing Module(Audio CD/ATRAC CD/MP3 CD) : 4.3.01.14050

Px Engine: 3.4.36.500

Link to comment
Share on other sites

SonicStage : 4.3.01.14050

SonicStage Add-on for 4.3 Upgrade : 4.3.01.14050

OpenMG Secure Module : 4.7.00.12140

MagicGate Memory Stick Device : 4.7.00.12140

NW-E2, NW-E3, NW-E5 and NW-E8P : 4.7.00.12140

OpenMG CD : 4.7.00.12140

M.S. PRO : 4.7.00.12140

CD Walkman : 4.7.00.12140

ATRAC Audio Device with Intelligent function : 4.7.00.12140

Hi-MD : 4.7.00.12140

Music Clip, NW-S4, NW-E7 and NW-E10 : 4.7.00.12140

ATRAC Audio Device : 4.7.00.12140

Net MD : 4.7.00.12140

EMD Plug-in: 4.3.01.14020

CD-R Writing Module(Audio CD/ATRAC CD/MP3 CD) : 4.3.01.14050

Px Engine: 3.4.36.500

Looks like the original version with a new installation script.

Edited by Avrin
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...