logoalt Hacker News

orra12/09/20241 replyview on HN

Whilst this is true, it looks like OpenWRT fixed the hash truncation but not the command injection.

I hope they're planning on fixing the command injection. As the blog post says, the created images are signed. Even without the signing, it's code execution from untrusted user input. And of course vulnerabilities can be strung together (just like in this hash collision case).


Replies

cesarb12/09/2024

> Whilst this is true, it looks like OpenWRT fixed the hash truncation but not the command injection.

They did fix both AFAIK, the command injection fix is https://github.com/openwrt/asu/commit/deadda8097d49500260b17... (source: https://openwrt.org/advisory/2024-12-06).

show 1 reply