Re: Attended Sysupgrade Server CVE-2024-54143

2024-12-07 Thread Paul Spooren
Hey again, The security researcher published an article describing the details, a good read indeed. https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/ Best, Paul > On 6. Dec 2024, at 23:42, Christian Marangi (Ansuel) > wrote: > > Forwarding this also to de

Re: Attended Sysupgrade Server CVE-2024-54143

2024-12-06 Thread Goetz Goerisch
Dear Christian and all who were involved, Thank you! Is there an ETA when the official sysupgrade server will be available again? Currently it is not reachable. Thank you very much. Goetz Am Fr., 6. Dez. 2024 um 23:42 Uhr schrieb Christian Marangi (Ansuel) : > > Forwarding this also to devel

Attended Sysupgrade Server CVE-2024-54143

2024-12-06 Thread Christian Marangi (Ansuel)
Forwarding this also to devel list in case anyone might miss this. --- Hi, last Wednesday we got notified of a security issue of the sysupgrade server ASU[1]. It affected all ASU instances including the the official instance[2]. Official ASU instances runs on dedicated servers separate from OpenW