{"id":40697,"date":"2020-02-03T14:36:04","date_gmt":"2020-02-03T11:36:04","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/obnovlenie-openwrt-19-07-1-s-ustraneniem-uyazvimosti-dopuskayushhej-podmenu-paketov"},"modified":"2020-02-03T14:36:04","modified_gmt":"2020-02-03T11:36:04","slug":"obnovlenie-openwrt-19-07-1-s-ustraneniem-uyazvimosti-dopuskayushhej-podmenu-paketov","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/obnovlenie-openwrt-19-07-1-s-ustraneniem-uyazvimosti-dopuskayushhej-podmenu-paketov","title":{"rendered":"OpenWrt 19.07.1 update addressing a vulnerability allowing package substitution","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Correction releases of the OpenWrt distribution have been published <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.infradead.org\/pipermail\/openwrt-devel\/2020-January\/021541.html\"> 18.06.7<\/a><\/noindex> and  <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.infradead.org\/pipermail\/openwrt-devel\/2020-January\/021543.html\">19.07.1<\/a><\/noindex>, which address  <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.infradead.org\/pipermail\/openwrt-devel\/2020-January\/021544.html\">a critical vulnerability<\/a><\/noindex> (CVE-2020-7982) in the package manager <noindex><a rel=\"nofollow\" href=\"https:\/\/openwrt.org\/docs\/guide-user\/additional-software\/opkg\">opkg<\/a><\/noindex>, allowing for a MITM attack and the replacement of content downloaded from the repository package. Due to a bug in the checksum verification code, an attacker can create conditions under which the SHA-256 checksums found in the digitally signed package index are ignored, allowing circumventing the integrity checking mechanisms of the downloaded ipk resources.<\/p>\n<p>The problem has been present since February 2017, after <noindex><a rel=\"nofollow\" href=\"https:\/\/git.openwrt.org\/54cc7e3\">adding<\/a><\/noindex> code for ignoring leading whitespace before the checksum. Due to an error in skipping spaces, the pointer at the position in the string was not shifted, and the hex decoding loop for SHA-256 immediately returned control and returned a checksum of zero length. <\/p>\n<p>Since the opkg package manager in OpenWrt runs with root privileges, in the case of a MITM attack, an attacker can discreetly modify the ipk package being downloaded from the repository during the execution of the user's 'opkg install' command, and organize the execution of their code with root permissions by adding their own handler scripts to the package that are invoked during installation. To exploit the vulnerability, the attacker must also replace the correct and signed package index (for example, served from downloads.openwrt.org). The size of the modified package must match the original size specified in the index.<\/p>\n<p>In a situation where it is necessary to avoid updating the entire firmware, only the opkg package manager can be updated by executing the following commands:<\/p>\n<p>   cd \/tmp<br \/>\n   opkg update<br \/>\n   opkg download opkg<br \/>\n   zcat .\/opkg-lists\/openwrt_base | grep -A10 'Package: opkg' | grep SHA256sum<br \/>\n   sha256sum .\/opkg_2020-01-25-c09fe209-1_*.ipk<\/p>\n<p>Next, the displayed checksums should be compared, and if they match, execute:<\/p>\n<p>   opkg install .\/opkg_2020-01-25-c09fe209-1_*.ipk<\/p>\n<p>In the new versions, another <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.infradead.org\/pipermail\/openwrt-devel\/2020-January\/021545.html\">vulnerability<\/a><\/noindex> in the library <noindex><a rel=\"nofollow\" href=\"https:\/\/openwrt.org\/docs\/techref\/libubox\">libubox<\/a><\/noindex>, which can lead to a buffer overflow when processing in the function <noindex><a rel=\"nofollow\" href=\"https:\/\/lxr.openwrt.org\/ident?i=blobmsg_format_json\">blobmsg_format_json<\/a><\/noindex> specially formatted serialized binary data or data in JSON format. The library is used in distribution components such as netifd, procd, ubus, rpcd, and uhttpd, as well as in the package <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/openwrt\/packages\/blob\/master\/utils\/auc\/src\/auc.c#L676\">auc<\/a><\/noindex> (Attended sysUpgrade CLI). Buffer overflow occurs when transmitting large numeric attributes of type 'double' in blob blocks. You can check the system's vulnerability to this by executing the command:<\/p>\n<p>    $ ubus call luci getFeatures \\<br \/>\n       '{ 'banik': 00192200197600198000198100200400.1922 }'<\/p>\n<p>In addition to addressing vulnerabilities and fixing accumulated bugs in the OpenWrt 19.07.1 release, the Linux kernel version has also been updated (from 4.14.162 to 4.14.167), and issues with performance when using 5GHz frequencies have been resolved, enabling support for Ubiquiti Rocket M Titanium, Netgear WN2500RP v1,<br \/>\n   Zyxel NSA325, Netgear WNR3500 V2, Archer C6 v2, Ubiquiti EdgeRouter-X, Archer C20 v4, Archer C50 v4, Archer MR200, TL-WA801ND v5, HiWiFi HC5962, Xiaomi Mi Router 3 Pro, and Netgear R6350.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52287\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 OpenWrt 18.06.7 \u0438 19.07.1, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-7982) \u0432 \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u043c \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0435 opkg, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0438\u0442\u044c MITM-\u0430\u0442\u0430\u043a\u0443 \u0438 \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u043e\u0433\u043e \u0438\u0437 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f \u043f\u0430\u043a\u0435\u0442\u0430. \u0418\u0437-\u0437\u0430 \u043e\u0448\u0438\u0431\u043a\u0438 \u0432 \u043a\u043e\u0434\u0435 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c\u043d\u044b\u0445 \u0441\u0443\u043c\u043c, \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u043c\u043e\u0436\u0435\u0442 \u0441\u043e\u0437\u0434\u0430\u0442\u044c \u0443\u0441\u043b\u043e\u0432\u0438\u044f, \u043f\u0440\u0438 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c\u043d\u044b\u0435 \u0441\u0443\u043c\u043c\u044b SHA-256, \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0435 \u0432 \u0437\u0430\u0432\u0435\u0440\u0435\u043d\u043d\u043e\u043c \u0446\u0438\u0444\u0440\u043e\u0432\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u044c\u044e \u0438\u043d\u0434\u0435\u043a\u0441\u0435 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0431\u0443\u0434\u0443\u0442 \u0438\u0433\u043d\u043e\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u044b, \u0447\u0442\u043e \u0434\u0430\u0451\u0442 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-40697","post","type-post","status-publish","format-standard","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 OpenWrt 18.06.7 \u0438\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/obnovlenie-openwrt-19-07-1-s-ustraneniem-uyazvimosti-dopuskayushhej-podmenu-paketov\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 OpenWrt 19.07.1 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0434\u043e\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0435\u0439 \u043f\u043e\u0434\u043c\u0435\u043d\u0443 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 OpenWrt 18.06.7 \u0438\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/obnovlenie-openwrt-19-07-1-s-ustraneniem-uyazvimosti-dopuskayushhej-podmenu-paketov\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-03T11:36:04+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-03T11:36:04+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47OpenWrt 19.07.1 update addressing the vulnerability that allows package substitution | ProHoster","description":"Correction releases for the OpenWrt 18.06.7 distribution have been published and","canonical_url":"https:\/\/prohoster.info\/en\/blog\/obnovlenie-openwrt-19-07-1-s-ustraneniem-uyazvimosti-dopuskayushhej-podmenu-paketov","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 OpenWrt 19.07.1 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0434\u043e\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0435\u0439 \u043f\u043e\u0434\u043c\u0435\u043d\u0443 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 OpenWrt 18.06.7 \u0438","og:url":"https:\/\/prohoster.info\/en\/blog\/obnovlenie-openwrt-19-07-1-s-ustraneniem-uyazvimosti-dopuskayushhej-podmenu-paketov","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-03T11:36:04+00:00","article:modified_time":"2020-02-03T11:36:04+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"40697","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 00:32:41","updated":"2022-09-30 04:43:23","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/40697","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=40697"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/40697\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=40697"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=40697"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=40697"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}