PT-2022-16433 · Sonos · Sonos One Speaker

David Berard

+1

·

Published

2022-02-10

·

Updated

2022-03-07

·

CVE-2022-24049

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sonos One Speaker versions prior to 3.4.1 (S2 systems) Sonos One Speaker versions prior to 11.2.13 build 57923290 (S1 systems)
Description This issue allows remote attackers to execute arbitrary code on affected installations. Authentication is not required to exploit this issue. The specific flaw exists within the ALAC audio codec, resulting from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this issue to execute code in the context of root.
Recommendations For versions prior to 3.4.1 (S2 systems), update to version 3.4.1 or later. For versions prior to 11.2.13 build 57923290 (S1 systems), update to version 11.2.13 build 57923290 or later. As a temporary workaround, consider disabling the ALAC audio codec until a patch is available.

Fix

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24049
ZDI-22-261

Affected Products

Sonos One Speaker