freifunk-gluon / gluon

a modular framework for creating OpenWrt-based firmwares for wireless mesh nodes
https://gluon.readthedocs.io
Other
548 stars 324 forks source link

Privilege reduction for WAN dnsmasq #3175

Open neocturne opened 8 months ago

neocturne commented 8 months ago

OpenWrt reduces the risk of compromising the system through dnsmasq vulnerabilities in two ways:

We should look into making the same improvements for the WAN dnsmasq instance.

T-X commented 8 months ago

Especially as the dnsmasq code quality is quite... bad in my opinion... And we still have an open segfault in it. So sounds like a very good idea.