Home   ›   Support   ›   Security Notices
29 Aug 2006

Important Notice to Sony VAIO Personal Computer Owners with SonicStage 3.3 / 3.4, CONNECT Player and SonicStage Mastering Studio 2.1.00/2.2.01

Recently, security vulnerability has been found within a limited number of Sony's Software applications using the module supplied by Gracenote©. To date neither Sony nor Gracenote has received reports of any customers being affected by this issue. However, we take all security issues very seriously and are therefore providing information about this Gracenote© update to address the issue.

What is the issue?

Security vulnerability (also known as a "buffer overflow") has been found that exists in certain versions of an ActiveX control for the CD Information Retrieval Service provided by Gracenote that is used in certain Sony's software applications. This "buffer overflow" vulnerability could allow an attacker to load malicious code onto a user's system and then execute the code.

This issue only affects the Sony software applications listed below. Other Sony software that utilizes Gracenote's CD Database lookup features do not contain this security issue.

Affected Sony Products

VAIO computers using the following software:

  • CONNECT Player
  • SonicStage™ Version 3.3/3.4
  • SonicStage Mastering Studio™ Version 2.1.00/2.2.01

Available Download:

Filename: GracenoteUpdateForSony.exe
Download size: 2.89 MB
Updated on: 2006/06/28

Gracenote is providing the upgrade software on their website. For more detailed information, please click here.

smallLargeLarger Adjust Font Size
Print This Page

Not the product you are looking for?

Additional Resource

  • »

    Contacting Sony

    Got a suggestion, feedback or comment? We’re happy to hear from you!

  • »

    Service Centres

    List of Sony offices in Asia Pacific region that provide sales and after-sales service activities.

  • »

    Retail stores

    List of Sony retail shops in Asia Pacific region.