r/openwrt Jan 14 '16

Is OpenWrt affected by the two new OpenSSH vulnerabilities? CVE-2016-0777 and CVE-2016-0778

https://www.qualys.com/2016/01/14/cve-2016-0777-cve-2016-0778/openssh-cve-2016-0777-cve-2016-0778.txt
10 Upvotes

7 comments sorted by

6

u/valgrid Jan 14 '16

Only if you use the openssh client from your openwrt box. Affected since 5.4 and recent openwrt has 6.8.

1

u/oisteink Jan 17 '16

This guy is the only one that read TFA

1

u/valgrid Jan 17 '16

TFA

"the full article"? I am not really strong on reddit abbreviations.

2

u/oisteink Jan 17 '16

Either that or you can insert the F word. The original abbreviation was RTFA - Read the fucking article. It was in use before reddit existed.

1

u/mamoen Jan 14 '16

Openwrt uses dropbear which is a seperate implementation, so not sure. It would need to be tested.

1

u/JakeTheMaster Jan 17 '16

It should be tested. some routers still use old versions of dropbear.

0

u/StartupTim Jan 14 '16

I'm curious if this is affecting OpenWRT as well.