Article ID : 00181908 / Last Modified : 16/08/2017Print

Important Notice to Personal Audio Product Owners with SonicStage 3.3 / 3.4, and CONNECT Player

    2006-06-28

    Recently, security vulnerability has been found within a limited number of Sony’s Software applications using the module supplied by Gracenote®.  To date neither Sony nor Gracenote has received reports of any customers being affected by this issue. However, we take all security issues very seriously and are therefore providing information about this Gracenote® update to address the issue.

    What is the issue?

    Security vulnerability (also known as a “buffer overflow”) has been found that exists in certain versions of an ActiveX® control for the CD Information Retrieval Service provided by Gracenote that is used in certain Sony’s software applications. This "buffer overflow" vulnerability could allow an attacker to load malicious code onto a user's system and then execute the code.

    This issue only affects the Sony software applications listed below. Other Sony software that utilizes Gracenote's CD Database lookup features do not contain this security issue.

    Affected Sony Products

    Personal audio products using the following software:

    • CONNECT Player
    • SonicStage® Version 3.3/3.4

    Available Download:

    Filename: GracenoteUpdateForSony.exe
    Download size: 2.89 MB
    Updated on: 2006/06/28

    Gracenote is providing the upgrade software on their website. For more detailed information, please click here.