Live data from Hacker News

D-Link patch doesn’t address all bugs listed in their own security advisory

devttys0.com

1–10 of 86 posts

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#6
post #2

I guess this is a reminder that writing secure C is actually really, really hard.

Or a reminder that when someone sends you a list of things wrong, maybe you should read and understand it rather than applying a 2 second fix that doesn't actually fix anything?

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#8
I've just accepted that residential routers are full of assorted orifices (security holes, backdoors & holes in functionality).

Then again I'm not hiding anything dubious - if I was I'd install a firewall box asap. (And yes I know the "nothing to hide" slippery slope etc argument)

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#9
Interesting. The D-Link security advisory (http://securityadvisories.dlink.com/security/publication.asp...) states that the issue was only partially resolved. What was changed (aside from adding an additional buffer overflow) in the patch that attempted to alleviate these issues?
Post reply on HN