4 ms·
Yes it was fixed when pointed out to them, after all openwrt users from 18.06+ had been exposed to this for three years. There's no known way to guard against
by outsomnia 6y ago
Yes it was fixed when pointed out to them, after all openwrt users from 18.06+ had been exposed to this for three years. There's no known way to guard against bugs in the end, but... you can empirically test... they didn't check at all if their package signature check could detect tampering after patching it? For 3 years?
Then no infrastructure changes as a reaction to what happened? Like I said good for them, the PR mentions they will get some funding this is the kind of thing they can spend it on.