Home   ›   Support   ›   Download

SonicStage CP® (SonicStage® Ver.4.0/4.1/4.2/4.3) Security Update Program

Article ID:231346(modified 23 Mar 2011)

Applicable Models

CMT-A50, CMT-A70, CMT-CPZ1, CMT-GPZ6, CMT-HPR90, CMT-HPZ7, CMT-HPZ9, CMT-U1BT, D-NE20, D-NE20LS, D-NE320, D-NE320SP, D-NE326CK, D-NE330, D-NE331, D-NE336CK, D-NE520, D-NE720, D-NE720LS, D-NE730, D-NE820, D-NE820LS, D-NE830, D-NE830LS, D-NE920, D-NE920LS, D-NF420, D-NF430, D-NF431, MZ-DH10P, MZ-NH1, MZ-NH600, MZ-NH700, MZ-NH900, MZ-NHF800, MZ-RH1, MZ-RH10, MZ-RH710, MZ-RH910, NW-A1000, NW-A3000, NW-A605, NW-A607, NW-A608, NW-A805, NW-A806, NW-A808, NW-E002F, NW-E003F, NW-E005F, NW-E013F, NW-E015F, NW-E016F, NW-E103, NW-E105, NW-E303, NW-E305, NW-E307, NW-E403, NW-E405, NW-E407, NW-E50, NW-E503, NW-E505, NW-E507, NW-E70, NW-E90, NW-E99, NW-HD1, NW-HD3, NW-HD5, NW-MS11, NW-MS6, NW-MS7, NW-MS70D, NW-MS77DR, NW-MS9, NW-MS90D, NW-S202F, NW-S203F, NW-S205F, NW-S23, NW-S603, NW-S605, NW-S703F, NW-S705F, NW-S706F, SSCP Ver.4.0, SSCP Ver.4.2, SSCP Ver.4.3, ZS-SN10, ZS-XN30

What does this download do?

5th December, 2007

Sony today announced the release of a security update program to address potential security vulnerability resulting from a buffer overflow in some versions of SonicStageCP® music management software, announced by Sony on November 7th, 2007. SonicStage® users are requested to download the security update program in accordance with the following procedures.

Version of SonicStage® subject to security update

  • SonicStage® CP (SonicStage® Versions 4.0/4.1/4.2/4.3)
    *Upgraded SonicStage® versions are also subject to this security update.

Description of update

This security update program fixes a potential buffer overflow when importing certain malicious play list (m3u) files that could cause the above listed versions of SonicStage® to crash and execute an arbitrary code.
CVE-ID*: CVE-2007-5709
Sony gives credit to Secunia for discovering and reporting this issue.

*CVE (Common Vulnerabilities and Exposures) is a vulnerabilities issue list identification number.

Before Downloading the Security Update Program

How to Check Version Eligibility

  1. Start the SonicStage program.
  2. At the main program screen, click the Help option on the menu, and then click About SonicStage.
  3. At the About SonicStage window, check to see if the version number begins with 4.0, 4.1, 4.2, or 4.3. Only SonicStage versions 4.0/4.1/4.2/4.3 are subjected to the security update.

Important Notes

  • This update program is provided to users under the conditions of customer’s SonicStage® Software Legal Agreement.
  • To ensure that no other program interferes with the installation, save all work and close all other programs. The Taskbar should be clear of applications before proceeding.

Available Downloads:

SonicStage CP Security Update Program
File name: SonicStageSecurityUpdateProgram-
File size: 3.11 MB

Important Notes

For Windows Vista® and Windows XP® Users

When downloading the security update with Windows Vista® or Windows XP®, execute update after logging on with user name that belongs to computer manager or manager.

Windows Vista® may display dialog boxes such as "Windows® needs your permission to continue" which controls the user account.
Check the content and continue operations following the displayed announcement.

For Windows 2000® Users

When downloading the security update with Windows 2000 Professional®, use the “Administrator” (single-byte alphabet and numbers) account.

Not the product you are looking for?

Additional Resource

  • »

    Contacting Sony

    Got a suggestion, feedback or comment? We’re happy to hear from you!

  • »

    Service Centres

    List of Sony offices in Asia Pacific region that provide sales and after-sales service activities.

  • »

    Retail stores

    List of Sony retail shops in Asia Pacific region.