4 ms·
Whilst this is true, it looks like OpenWRT fixed the hash truncation but not the command injection. I hope they're planning on fixing the command injection. As
by orra 2y ago
Whilst this is true, it looks like OpenWRT fixed the hash truncation but not the command injection.
I hope they're planning on fixing the command injection. As the blog post says, the created images are signed. Even without the signing, it's code execution from untrusted user input. And of course vulnerabilities can be strung together (just like in this hash collision case).
- cesarb 2y ago> Whilst this is true, it looks like OpenWRT fixed the hash truncation but not the command injection. They did fix both AFAIK, the command injection fix is https://github.com/openwrt/asu/commit/deadda8097d49500260b171d2bf8ad2b048da04b https://github.com/openwrt/asu/commit/deadda8097d49500260b17... (source: https://openwrt.org/advisory/2024-12-06 https://openwrt.org/advisory/2024-12-06).
- orra 2y agoThanks for the correction and sorry for the mistake. I skimmed the changes but apparently not very well.