LAN.ST  

Go Back   LAN.ST > Forum > Console Hacking & Development > Sony PlayStation Portable

Sony PlayStation Portable Sony PlayStation Portable related development discussion.

Reply
 
Thread Tools Display Modes
  #1  
Old 12-17-2008, 08:26 AM
wololo wololo is offline
Moderator
 
Join Date: Dec 2008
Posts: 202
Default libTiff vulnerability

I think the PSP is using the libtiff for image decoding...
would it be worth it looking into this vulnerability ? (it's a bit old, end of august)
http://secunia.com/advisories/31610/

Sorry if that's not the kind of talk allowed here

Edit: all my current findings on this vulnerability are summed up a few pages later in this same thread : http://lan.st/showthread.php?p=13084#post13084

Edit2: changed the title for a less confusing one

Last edited by wololo; 02-04-2009 at 12:28 AM.
Reply With Quote
  #2  
Old 12-17-2008, 07:12 PM
Torch Torch is offline
Junior Member
 
Join Date: Oct 2007
Posts: 27
Default

Depends on whether the PSP implementation can be made to jump into code that we plant. Only those who've fully studied the lib on the PSP will know.
Reply With Quote
  #3  
Old 12-17-2008, 07:23 PM
Jachra Jachra is offline
Senior Member
 
Join Date: Oct 2007
Posts: 203
Default

Quote:
Multiple buffer underflows in the (1) LZWDecode, (2) LZWDecodeCompat, and (3) LZWDecodeVector functions in tif_lzw.c in the LZW decoder in LibTIFF 3.8.2 and earlier allow context-dependent attackers to execute arbitrary code via a crafted TIFF file, related to improper handling of the CODE_CLEAR code.
It might be usable, but further study must show that
Reply With Quote
  #4  
Old 12-18-2008, 01:33 AM
arnold arnold is offline
Senior Member
 
Join Date: Feb 2007
Location: Where Specter lives.
Posts: 291
Default

Isn't libtiff old? Huh?

-Arnold
__________________
irc.malloc.us
#Arnold

Come and chat with Arnie
UTOPIA Project Awesomeness

http://arnold.hyperphp.com/forums

Reply With Quote
  #5  
Old 12-18-2008, 02:20 AM
Hellcat Hellcat is offline
Supervisor
 
Join Date: Jan 2008
Posts: 178
Default

That's been fixed in FW 2.00, guys.... o_O
__________________
irc.malloc.us #Hellcat
Reply With Quote
  #6  
Old 12-18-2008, 04:00 AM
Torch Torch is offline
Junior Member
 
Join Date: Oct 2007
Posts: 27
Default

Quote:
Originally Posted by Hellcat View Post
That's been fixed in FW 2.00, guys.... o_O
No this is a new exploit.

If its actually usable, then its just what we need. A user mode exploit to complement the kernel mode exploits that certain people say exist in current firmware.
Reply With Quote
  #7  
Old 12-18-2008, 04:29 AM
arnold arnold is offline
Senior Member
 
Join Date: Feb 2007
Location: Where Specter lives.
Posts: 291
Default

Can't we just hold as long as we can until it is completely necessary to use new user mode exploits? That way, Sony won't block it. Yet.

-Arnold
__________________
irc.malloc.us
#Arnold

Come and chat with Arnie
UTOPIA Project Awesomeness

http://arnold.hyperphp.com/forums

Reply With Quote
  #8  
Old 12-18-2008, 07:34 PM
Jachra Jachra is offline
Senior Member
 
Join Date: Oct 2007
Posts: 203
Default

Quote:
Originally Posted by arnold View Post
Can't we just hold as long as we can until it is completely necessary to use new user mode exploits? That way, Sony won't block it. Yet.

-Arnold
We can safely assume that this possible exploit will be patched in the next firmware. Sony knows from the past events that the scene will try to use this and will not leave unpatched.
Reply With Quote
  #9  
Old 12-19-2008, 07:33 AM
arnold arnold is offline
Senior Member
 
Join Date: Feb 2007
Location: Where Specter lives.
Posts: 291
Default

Unless they are silly.

-Arnold
__________________
irc.malloc.us
#Arnold

Come and chat with Arnie
UTOPIA Project Awesomeness

http://arnold.hyperphp.com/forums

Reply With Quote
  #10  
Old 12-21-2008, 09:38 AM
wololo wololo is offline
Moderator
 
Join Date: Dec 2008
Posts: 202
Default

Quote:
Originally Posted by Jachra View Post
We can safely assume that this possible exploit will be patched in the next firmware. Sony knows from the past events that the scene will try to use this and will not leave unpatched.
That's my concern. The exploit was found on 8/26, and the 4.20 firmware which ships with psp3000 was released in october...
Chances are high that firmware 4.20 already has a patch for this issue, unfortunately there is no "proof of concept" file available publicly to test...
Reply With Quote
Reply

  LAN.ST > Console Hacking & Development > Sony PlayStation Portable

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Exploit found in flash player. Squirrel Sony PlayStation Portable 6 08-02-2007 06:11 AM
Possible Exploit Kwastie Sony PlayStation Portable 10 06-14-2007 06:13 PM
3.10 Possible Exploit. Mentality Sony PlayStation Portable 1 02-03-2007 05:22 PM
new exploit found! SpectroPlasm Sony PlayStation Portable 4 12-22-2006 02:00 AM


All times are GMT +1. The time now is 04:16 AM.

Design Developed by CompleteGFX
Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.