Sony PC Companion 'DownloadURLToFile()' Function Stack Based Buffer Overflow Vulnerability
BID:57028
Info
Sony PC Companion 'DownloadURLToFile()' Function Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 57028 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2012 12:00AM |
| Updated: | Dec 20 2012 12:00AM |
| Credit: | Gjoko Krstic |
| Vulnerable: |
Sony PC Companion 2.10.115 Sony PC Companion 2.10.108 |
| Not Vulnerable: | |
Discussion
Sony PC Companion 'DownloadURLToFile()' Function Stack Based Buffer Overflow Vulnerability
Sony PC Companion is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary-checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
Sony PC Companion 2.10.115 and 2.10.108 are vulnerable; other versions may also be affected.
Sony PC Companion is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary-checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
Sony PC Companion 2.10.115 and 2.10.108 are vulnerable; other versions may also be affected.
Exploit / POC
Sony PC Companion 'DownloadURLToFile()' Function Stack Based Buffer Overflow Vulnerability
Proof-of-concept is available; please see the references for more information.
Proof-of-concept is available; please see the references for more information.
Solution / Fix
Sony PC Companion 'DownloadURLToFile()' Function Stack Based Buffer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].