Vulnerabilities / Threats
7/2/2008
07:53 PM
Connect Directly
RSS
E-Mail
50%
50%

Sony Confirms Pulling PS3 Firmware Update

The company released firmware 2.40 Tuesday, and reports of problems started flowing in soon after on the official PlayStation 3 message board.

Sony on Wednesday confirmed that it has pulled the latest firmware update for PlayStation 3, because of reports from customers that it has caused their systems to stop working.

Sony released firmware 2.40 Tuesday, and reports of problems started flowing in soon after on the official PS3 message board.

"I downloaded version 2.40, put in Metal Gear Solid 4 [video game] and I get a black screen forever," one customer wrote. "I can't even get demos to start."

A Sony spokesman confirmed that the company pulled the firmware off its servers while it investigates the problem, which he said was experienced by a "limited number of consumers."

"In order to further assess the issue, we have temporarily taken the firmware offline for further testing," the spokesman said in an e-mail to InformationWeek following a request for comment. "We are working diligently to isolate the problem for those few consumers and to identify a solution before we put the firmware back up."

The problem was first reported by the video game site Joystiq.

Key improvements in the latest firmware are in-game access to instant messaging to communicate with other players and other PS3 features, such as checking downloads, changing settings, and playing music from the user's library. In addition, the firmware introduces a trophy system to award players for game performance.

Meanwhile, a security firm on Tuesday reported that Sony USA's PlayStation Web site had been the victim of a "SQL injection attack."

SophosLabs said that visiting the site ran a script that pretended to do an online security scan of the visitor's computer, and then presented a bogus warning message that the PC was infected with malware. "Users frightened by the scareware 'warnings' might rush to spend money on useless software," the security firm said in its blog.

SQL injection attacks involve passing malicious code to SQL databases as user input. An improperly configured or vulnerable SQL application can be made to execute that input. All that's needed is to add HTML into a Web page that calls a script on a malicious site.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Must Reads - September 25, 2014
Dark Reading's new Must Reads is a compendium of our best recent coverage of identity and access management. Learn about access control in the age of HTML5, how to improve authentication, why Active Directory is dead, and more.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5619
Published: 2014-09-29
The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activities, as demonstrated by Flame.

CVE-2012-5621
Published: 2014-09-29
lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connection with a party name that contains invalid UTF-8 strings.

CVE-2012-6107
Published: 2014-09-29
Apache Axis2/C does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVE-2012-6110
Published: 2014-09-29
bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job, which allows local users to modify job files and send spam messages by accessing an open file descriptor.

CVE-2013-1874
Published: 2014-09-29
Untrusted search path vulnerability in csi in Chicken before 4.8.2 allows local users to execute arbitrary code via a Trojan horse .csirc in the current working directory.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
In our next Dark Reading Radio broadcast, we’ll take a close look at some of the latest research and practices in application security.