[NOT APPLICABLE]OpenSSL 2 New High-Severity Vulnerabilities

Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions
Author Message
mac913
DD-WRT Guru


Joined: 02 May 2008
Posts: 1848
Location: Canada

PostPosted: Thu Nov 03, 2022 1:08    Post subject: [NOT APPLICABLE]OpenSSL 2 New High-Severity Vulnerabilities Reply with quote
Fixed in OpenSSL 3.0.7 (git commit) (Affected 3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6)

https://thehackernews.com/2022/11/just-in-openssl-releases-patch-for-2.html

_________________
Home Network on Telus 1Gb PureFibre - 10GbE Copper Backbone
2x R7800 - Gateway & WiFi & 3xWireGuard - DDWRT r53562 Std k4.9

Off Site 1

R7000 - Gateway & WiFi & WireGuard - DDWRT r54517 Std
E3000 - Station Bridge - DDWRT r49626 Mega K4.4

Off Site 2

R7000 - Gateway & WiFi - DDWRT r54517 Std
E2000 - Wired ISP IPTV PVR Blocker - DDWRT r35531


YAMon 3.4.6 | DNSCrypt-Proxy V2
Sponsor
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1952

PostPosted: Thu Nov 03, 2022 1:33    Post subject: Reply with quote
DD-WRT is not using OpenSSL v3.x.x

https://github.com/mirror/dd-wrt/blob/master/src/router/openssl/CHANGES

https://github.com/mirror/dd-wrt/commit/8d15d51a6eeaccf4a639c13850eaf32522ab8f1a

https://github.com/mirror/dd-wrt/commit/ff7019701a9566f18f3c77841ca957aad04d9380

_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
mrjcd
DD-WRT Guru


Joined: 31 Jan 2015
Posts: 6291
Location: Texas

PostPosted: Thu Nov 03, 2022 2:05    Post subject: Reply with quote
prolly be a bit before DD-WRT gets there Twisted Evil

machine imma on right now
Code:
mrjcd@daDeb:~$ openssl version
OpenSSL 3.0.5 5 Jul 2022 (Library: OpenSSL 3.0.5 5 Jul 2022)

and then again across the room running---
Code:
Server Version: Apache/2.4.54 (Debian) OpenSSL/3.0.7
Server MPM: prefork
Server Built: 2022-10-12T07:20:52
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1952

PostPosted: Thu Nov 03, 2022 2:07    Post subject: Reply with quote
If you back-track history on the folder in the repo, OpenSSL 3.x.x was tried and reverted. To go along with previous post:

https://www.openssl.org/news/secadv/20221101.txt

https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/

OpenSSL v1.1.x is not affected because the code that the vulnerabilities center around were introduced in v3.0.0.

DD-WRT does need to apply the bugfix and update to 1.1.1s, though.

_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
mrjcd
DD-WRT Guru


Joined: 31 Jan 2015
Posts: 6291
Location: Texas

PostPosted: Thu Nov 03, 2022 2:17    Post subject: Re: OpenSSL Releases Patch for 2 New High-Severity Vulnerabi Reply with quote
mac913 wrote:
https://thehackernews.com/2022/11/just-in-openssl-releases-patch-for-2.html
from that page:
"It's worth noting that the commonly deployed OpenSSL 1.x versions are not vulnerable."

EA8500 r50786 is on OpenSSL 1.1.1r
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6446
Location: UK, London, just across the river..

PostPosted: Thu Nov 03, 2022 9:13    Post subject: Reply with quote
01-Nov-2022OpenSSL 1.1.1s is now available, including bug fixes….

i wonder how to manually update entware libopenssl as entware guys are not very updated...
is there a way to manually update/prepare package …..i tried once to fiddle with entware make... but was not very successful…

Anyway BS keeps those updated asap..

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913


Last edited by Alozaros on Thu Nov 03, 2022 19:09; edited 1 time in total
the-joker
DD-WRT Developer/Maintainer


Joined: 31 Jul 2021
Posts: 2146
Location: All over YOUR webs

PostPosted: Thu Nov 03, 2022 11:58    Post subject: Reply with quote
https://svn.dd-wrt.com/changeset/50797
_________________
Saving your retinas from the burn!🔥
DD-WRT Inspired themes for routers
DD-WRT Inspired themes for the phpBB Forum
DD-WRT Inspired themes for the SVN Trac & FTP site
Join in for a chat @ #style_it_themes_public:matrix.org or #style_it_themes:discord

DD-WRT UI Themes Bug Reporting and Discussion thread

Router: ANus RT-AC68U E1 (recognized as C1)
mac913
DD-WRT Guru


Joined: 02 May 2008
Posts: 1848
Location: Canada

PostPosted: Thu Nov 03, 2022 14:19    Post subject: Reply with quote
Thanks for the update, everyone!
_________________
Home Network on Telus 1Gb PureFibre - 10GbE Copper Backbone
2x R7800 - Gateway & WiFi & 3xWireGuard - DDWRT r53562 Std k4.9

Off Site 1

R7000 - Gateway & WiFi & WireGuard - DDWRT r54517 Std
E3000 - Station Bridge - DDWRT r49626 Mega K4.4

Off Site 2

R7000 - Gateway & WiFi - DDWRT r54517 Std
E2000 - Wired ISP IPTV PVR Blocker - DDWRT r35531


YAMon 3.4.6 | DNSCrypt-Proxy V2
mac913
DD-WRT Guru


Joined: 02 May 2008
Posts: 1848
Location: Canada

PostPosted: Thu Nov 03, 2022 14:26    Post subject: Reply with quote
the-joker wrote:
https://svn.dd-wrt.com/changeset/50797


I'll wait for the next build release for the latest OpenSSL 1.1.1s 1 Nov 2022.

Thanks!

_________________
Home Network on Telus 1Gb PureFibre - 10GbE Copper Backbone
2x R7800 - Gateway & WiFi & 3xWireGuard - DDWRT r53562 Std k4.9

Off Site 1

R7000 - Gateway & WiFi & WireGuard - DDWRT r54517 Std
E3000 - Station Bridge - DDWRT r49626 Mega K4.4

Off Site 2

R7000 - Gateway & WiFi - DDWRT r54517 Std
E2000 - Wired ISP IPTV PVR Blocker - DDWRT r35531


YAMon 3.4.6 | DNSCrypt-Proxy V2
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14243
Location: Texas, USA

PostPosted: Thu Nov 03, 2022 16:03    Post subject: Reply with quote
dale_gribble39 wrote:
DD-WRT does need to apply the bugfix and update to 1.1.1s, though.

Alozaros wrote:
01-Nov-2022OpenSSL 1.1.1s is now available, including bug fixes….
....
Anyway BS keeps those updated asap..

the-joker wrote:
https://svn.dd-wrt.com/changeset/50797

You're welcome. I don't usually nudge BrainSlayer as he is rather particular about "bully moves" (i.e. tickets in Trac to update packages and such), but I contacted him last night about this thread and the update for 1.1.1s, as I'm sure there were others who contacted him about it as well...

P.S. the change in "quote" handling fscked up urls in quotes in the forum, so might as well always use the url tags Rolling Eyes

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum