Sony: It Just Keeps Coming
Dec. 7th, 2005 09:53 amOn top of everything else, Sony's DRM software has a privilege-escalation security flaw. Those few Windows users who don't run as administrator are screwed too. Yay!
Sony BMG Urges Security Fix for CDs
By ALEX VEIGA, AP Business Writer Tue Dec 6,11:29 PM ET
http://news.yahoo.com/s/ap/20051207/ap_on_hi_te/sony_copy_protection
LOS ANGELES - Sony BMG Music Entertainment said Tuesday some 5.7 million of its CDs were shipped with anti-piracy technology that requires a new software patch to plug a potential security breach in computers used to play the CDs.
The security vulnerability was discovered by online civil liberty group Electronic Frontier Foundation and brought to the attention of Sony BMG, which has been under fire in recent weeks over security issues with an unrelated CD copy-protection plan.
[...]
"It's a privileged escalation attack," said Kurt Opsahl, an EFF staff attorney. "On Windows you can have users with different privileges, and because of security weakness in the permissions of a folder, it allows a low-ranked user to act as a high-ranked user."
[More at URL]
Sony BMG Urges Security Fix for CDs
By ALEX VEIGA, AP Business Writer Tue Dec 6,11:29 PM ET
http://news.yahoo.com/s/ap/20051207/ap_on_hi_te/sony_copy_protection
LOS ANGELES - Sony BMG Music Entertainment said Tuesday some 5.7 million of its CDs were shipped with anti-piracy technology that requires a new software patch to plug a potential security breach in computers used to play the CDs.
The security vulnerability was discovered by online civil liberty group Electronic Frontier Foundation and brought to the attention of Sony BMG, which has been under fire in recent weeks over security issues with an unrelated CD copy-protection plan.
[...]
"It's a privileged escalation attack," said Kurt Opsahl, an EFF staff attorney. "On Windows you can have users with different privileges, and because of security weakness in the permissions of a folder, it allows a low-ranked user to act as a high-ranked user."
[More at URL]