Release date:
Updated on:
Affected Systems:
Sonymobile PC Companion 2.10.115
Sonymobile PC Companion 2.10.108
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57016
Sony PC Companion is a tool and application that connects devices to computers.
Sony PC Companion 2.10.115, 2.10.108 in its PluginManager. when the Admin_RemoveDirectory function in the dll processes the 'path' variable value, a boundary error occurs. Remote attackers can exploit this vulnerability to cause stack buffer overflow and arbitrary code execution by constructing long strings.
<* Source: Gjoko Krstic (liquidworm@gmail.com)
Link: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2012-5120.php
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
--------------------------------------------------------------------------------
STATUS_STACK_BUFFER_OVERRUN encountered
(1e5c. 1b34): Break instruction exception-code 80000003 (first chance)
Eax = 00000000 ebx = 6348e958 ecx = 75b1de28 edx = 0013e505 esi = 00000000 edi = 0013ed88
Eip = 75b1dca5 esp = 0013e74c ebp = 0013e7c8 iopl = 0 nv up ei pl zr na pe nc
Cs = 001b ss = 0023 ds = 0023 es = 0023 fs = 003b gs = 0000 efl = 00000246
KERNEL32! FormatMessageA + 0x13c85:
75b1dca5 cc int 3
0: 000>! Exchain
0013e7b8: KERNEL32! RegSaveKeyExA + 3e9 (75b49b72)
0013f114: 00430043
Invalid exception stacks at 00420042
0: 000> d 0013f114
0013f114 42 00 42 00 43 00 43 00-44 00 44 00 44 00 44 00 B. B .C. C.D. D.
0013f124 44 00 44 00 44 00 44 00-44 00 44 00 44 00 D.
0013f134 44 00 44 00 44 00-44 00 44 00 44 00 44 00 D.
0013f144 44 00 44 00 44 00-44 00 44 00 44 00 44 00 D.
0013f154 44 00 44 00 44 00-44 00 44 00 44 00 44 00 D.
0013f164 44 00 44 00 44 00-44 00 44 00 44 00 44 00 D.
0013f174 44 00 44 00 44 00-44 00 44 00 44 00 44 00 D.
0013f184 44 00 44 00 44 00-44 00 44 00 44 00 44 00 D.
0: 000>
--------------------------------------------------------------------------------
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Sonymobile
----------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.sonymobile.com/cn/