Discussion:
[OpenWrt-Users] Multiple vulnerabilities in dnsmasq before 2.78
Jay Carlson
2017-10-05 16:39:12 UTC
Permalink
dnsmasq has severe vulnerabilities until 2.78.

https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html

These include remote code execution.

1) Do these vulns affect CC installations (of which there are many)?

2) Could a revised dnsmasq be built, or is the upgrade path LEDE?

--
Jay Carlson
***@nop.com
Zoltan HERPAI
2017-10-05 17:15:46 UTC
Permalink
Post by Jay Carlson
dnsmasq has severe vulnerabilities until 2.78.
https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html
These include remote code execution.
1) Do these vulns affect CC installations (of which there are many)?
2) Could a revised dnsmasq be built, or is the upgrade path LEDE?
An announcement will be sent out tonight. Source trees for trunk/master
and CC are already updated (see github), binary packages will be built
by the buildbots in the next few hours for trunk.

Regards,
-w-
Andreas Ziegler
2017-10-06 07:31:38 UTC
Permalink
Post by Jay Carlson
2) Could a revised dnsmasq be built, or is the upgrade path LEDE?
as OpenWrt is barely updated, yes LEDE is the upgrade path.

soon, LEDE will be re-branded to OpenWrt, according to the plans i read
Benjamin Henrion
2017-10-06 07:33:55 UTC
Permalink
Post by Andreas Ziegler
Post by Jay Carlson
2) Could a revised dnsmasq be built, or is the upgrade path LEDE?
as OpenWrt is barely updated, yes LEDE is the upgrade path.
Well, security updates do not mean you have to upgrade your full
distro. We are talking about one package here, no big deal.
Post by Andreas Ziegler
soon, LEDE will be re-branded to OpenWrt, according to the plans i read
Let's wait and see.
--
Benjamin Henrion <bhenrion at ffii.org>
FFII Brussels - +32-484-566109 - +32-2-3500762
"In July 2005, after several failed attempts to legalise software
patents in Europe, the patent establishment changed its strategy.
Instead of explicitly seeking to sanction the patentability of
software, they are now seeking to create a central European patent
court, which would establish and enforce patentability rules in their
favor, without any possibility of correction by competing courts or
democratically elected legislators."
Loading...