3 ms·
That is indeed the theory. But the point here is how openwrt broke that "last / only line of defence" package signature check and nobody noticed for three year
by outsomnia 6y ago
That is indeed the theory. But the point here is how openwrt broke that "last / only line of defence" package signature check and nobody noticed for three years and two major releases.
- dastx 6y agoI am not aware of this. What happened?
- outsomnia 6y agoAs I linked above, introduced Feb 2017 found Jan 2020 https://openwrt.org/advisory/2020-01-31-1 https://openwrt.org/advisory/2020-01-31-1 A bug in the package list parse logic of OpenWrt's opkg fork caused the package manager to ignore SHA-256 checksums embedded in the signed repository index, effectively bypassing integrity checking of downloaded .ipk artifacts.