lixuewei / rt-n56u

Automatically exported from code.google.com/p/rt-n56u
0 stars 0 forks source link

schedule to commit security fixes from ASUS RT-N56U Firmware Version 3.0.0.4.374.5656 #1252

Closed GoogleCodeExporter closed 9 years ago

GoogleCodeExporter commented 9 years ago
Dear  friends,  
are there any plans to incorporate these fixes into your build ?

http://support.asus.com/download.aspx?SLanguage=en-us&m=rt-n56u

ASUS RT-N56U Firmware Version 3.0.0.4.374.5656
Security related issues:
1. Fixed remote command execution vulnerability
2. Fixed parameters buffer overflow vulnerability
3. Fixed XSS(Cross Site Scripting) vulnerability
4. Fixed CSRF(Cross Site Request Forgery) vulnerability
5. Added auto logout function. The timeout time can be configured in - 
Administration--> System
6. Included patches related to network map. Thanks for Merlin's contribution.
7. Fixed password disclosure in source code when adminstrator logged in. 

Original issue reported on code.google.com by erez.sht...@gmail.com on 19 May 2014 at 2:23

GoogleCodeExporter commented 9 years ago
Do we have this issues in our firmware??? 
The first time I hear about this problem. 

Are you sure about this fact?

Original comment by Dr.Sydorenko.O on 23 May 2014 at 10:08

GoogleCodeExporter commented 9 years ago
[deleted comment]
GoogleCodeExporter commented 9 years ago
[deleted comment]
GoogleCodeExporter commented 9 years ago
I can take a look at the remote command execution vuln this evening, but 
judging from your linkedIn profile you might be better suited for the task.

As for the hosts-file provided from winhelp, I like to think that the sheer 
size (500 kb) is the issue. I supposed one could go about and create a symlink 
and put it in /tmp.

Filesystem                Size      Used Available Use% Mounted on
tmpfs                    24.0M     72.0K     23.9M   0% /tmp

/Kitch

Original comment by kitch2400 on 24 May 2014 at 10:09

GoogleCodeExporter commented 9 years ago
RTFM, try to use the search systems

Original comment by Dr.Sydorenko.O on 28 May 2014 at 6:14