[Log In ] [New Posts] []
Go Back   GotApex? Forums Forums > General Topics > Software, OS, and the Internet
User Name
Password

Reply
 
Thread Tools Search this Thread Display Modes
Old 11-17-2005, 06:41 AM   #1
TruckStuff
Commander
 
Join Date: Jun 2005
Posts: 1,335
Sony: First they installed XCP, now they can't uninstall it

Security issues found in Sony's XCP uninstaller:

http://secunia.com/advisories/17610/
Quote:
Sony CD First4Internet XCP Uninstallation ActiveX Control Vulnerability

Secunia Advisory: SA17610 Print Advisory
Release Date: 2005-11-16

Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched

Software: First4Internet XCP Content Management

Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.

Description:
A vulnerability has been reported in First4Internet XCP's uninstallation ActiveX control, which potentially can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to the "CodeSupport.ocx" ActiveX control that is installed via Internet Explorer when the user un-installs the XCP DRM software by visiting the vendor's website. The ActiveX control is marked safe-for-scripting and supports several potentially dangerous methods like "RebootMachine", "InstallUpdate", and "IsAdministrator". This may be exploited to install arbitrary code on the user's system.

Successful exploitation requires that the user visits a malicious website.

The vulnerability is related to:
SA17408

Solution:
Remove the ActiveX control from the system if it is installed.

Provided and/or discovered by:
Muzzy, J. Alex Halderman, and Ed Felten.

Original Advisory:
http://www.freedom-to-tinker.com/?p=927
http://hack.fi/~muzzy/sony-drm/

Other References:
SA17408:
http://secunia.com/advisories/17408/
__________________
DISCLAIMER
The preceding statements are meant to be taken as a whole, in their entirety. They may not be quoted in part and then used to flame me. They also do not imply that I believe the exact opposite of their meaning. They do not make any implication about any group, race, ethnicity, age group, or other cohort beyond what is stated above. They do not make any implications at all. They have no "tone" or "attitude." They are words. Nothing more.
TruckStuff is offline   Reply With Quote
Old 11-17-2005, 08:40 AM   #2
mcs328
Admiral
 
mcs328's Avatar
 
Join Date: Feb 2001
Location: Maryland
Posts: 6,578
http://www.gotapex.com/forums/showthread.php?t=93369 (Got|Rootkit?)

The cure is worse than the poison it seems.
__________________
mcs328 is offline   Reply With Quote
Old 11-17-2005, 09:00 AM   #3
Jcranmer
Commander
 
Jcranmer's Avatar
 
Join Date: Jan 2001
Location: Pekin, IN
Posts: 1,377
Oh that's just great. Tell me again why people should by CDs instead of just downloading mp3s?
Jcranmer is offline   Reply With Quote
Old 11-17-2005, 02:09 PM   #4
zero2dash
Commander
 
zero2dash's Avatar
 
Join Date: Dec 2000
Location: Fenton, MO - but I wish I was at the beach. ANY beach.
Posts: 1,367
Send a message via Yahoo to zero2dash
Quote:
Originally Posted by Jcranmer
Oh that's just great. Tell me again why people should by CDs instead of just downloading mp3s?

zero2dash is offline   Reply With Quote
Old 11-17-2005, 02:23 PM   #5
gear02
Admiral
 
gear02's Avatar
 
Join Date: Apr 2000
Location: Seattle, WA
Posts: 7,223
Send a message via ICQ to gear02 Send a message via AIM to gear02 Send a message via Yahoo to gear02
please oh please let Sony burn to the ground because of this. Let it be a lesson to those damned DRM purveyors who think consumers will bend backwards for their IP.
gear02 is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -7. The time now is 08:26 PM.