Sony PC Companion Admin_RemoveDirectory () Stack Buffer Overflow Vulnerability

Source: Internet
Author: User

Release date:
Updated on:

Affected Systems:
Sonymobile PC Companion 2.10.115
Sonymobile PC Companion 2.10.108
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57016

Sony PC Companion is a tool and application that connects devices to computers.

Sony PC Companion 2.10.115, 2.10.108 in its PluginManager. when the Admin_RemoveDirectory function in the dll processes the 'path' variable value, a boundary error occurs. Remote attackers can exploit this vulnerability to cause stack buffer overflow and arbitrary code execution by constructing long strings.

<* Source: Gjoko Krstic (liquidworm@gmail.com)

Link: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2012-5120.php
*>

Test method:
--------------------------------------------------------------------------------

Alert

The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!

--------------------------------------------------------------------------------

STATUS_STACK_BUFFER_OVERRUN encountered
(1e5c. 1b34): Break instruction exception-code 80000003 (first chance)
Eax = 00000000 ebx = 6348e958 ecx = 75b1de28 edx = 0013e505 esi = 00000000 edi = 0013ed88
Eip = 75b1dca5 esp = 0013e74c ebp = 0013e7c8 iopl = 0 nv up ei pl zr na pe nc
Cs = 001b ss = 0023 ds = 0023 es = 0023 fs = 003b gs = 0000 efl = 00000246
KERNEL32! FormatMessageA + 0x13c85:
75b1dca5 cc int 3
0: 000>! Exchain
0013e7b8: KERNEL32! RegSaveKeyExA + 3e9 (75b49b72)
0013f114: 00430043
Invalid exception stacks at 00420042
0: 000> d 0013f114
0013f114 42 00 42 00 43 00 43 00-44 00 44 00 44 00 44 00 B. B .C. C.D. D.
0013f124 44 00 44 00 44 00 44 00-44 00 44 00 44 00 D.
0013f134 44 00 44 00 44 00-44 00 44 00 44 00 44 00 D.
0013f144 44 00 44 00 44 00-44 00 44 00 44 00 44 00 D.
0013f154 44 00 44 00 44 00-44 00 44 00 44 00 44 00 D.
0013f164 44 00 44 00 44 00-44 00 44 00 44 00 44 00 D.
0013f174 44 00 44 00 44 00-44 00 44 00 44 00 44 00 D.
0013f184 44 00 44 00 44 00-44 00 44 00 44 00 44 00 D.
0: 000>

--------------------------------------------------------------------------------

Suggestion:
--------------------------------------------------------------------------------
Vendor patch:

Sonymobile
----------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:

Http://www.sonymobile.com/cn/

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.