News:

RAID is not a replacement for a backup! Here's why.

Main Menu

Is my Buffalo Product (LS-CHL-V2 Firmware 1.60) affected by Heartbleed

Started by Florian71, April 10, 2014, 12:23:47 PM

Previous topic - Next topic

Florian71

Hi,
is the Firmware 1.60 running OpenSSL which contains the Heartbleed Security Issue?
Best regards,
   Florian

RandyChev

I'm concerned about the same thing. My "About" page shows "DD-WRT v24SP2-MULTI (07/05/12) std
(SVN revision 19438)".

According to DD-WRT any version from 19000-23882 are affected. My question is whether or not Buffalo will issue a firmware upgrade for this or if we have to go straight DD-WRT? I've been very happy with the Buffalo version compared to other versions I've used (perhaps because of the hardware it was used on).

Some sort of announcement would be in order.

Net7

Quote from: Florian71 on April 10, 2014, 12:23:47 PM
Hi,
is the Firmware 1.60 running OpenSSL which contains the Heartbleed Security Issue?
Best regards,
   Florian

That is a good question... I wonder what all else uses OpenSSL these days!

Also, looking at your unit model, it seems that while the US ends at v1.60, the EU has your unit at 1.68 like the rest of the LinkStation and LinkStation Pro model's! You might take a look into that if being up-to-date is your thing! (EU is normally hardware equal, they just release firmware or continue to release firmware earlier/later)


Net7

Quote from: RandyChev on April 10, 2014, 12:47:11 PM
I'm concerned about the same thing. My "About" page shows "DD-WRT v24SP2-MULTI (07/05/12) std
(SVN revision 19438)".

According to DD-WRT any version from 19000-23882 are affected. My question is whether or not Buffalo will issue a firmware upgrade for this or if we have to go straight DD-WRT? I've been very happy with the Buffalo version compared to other versions I've used (perhaps because of the hardware it was used on).

Some sort of announcement would be in order.

Come on guy... Thread jacking, especially when talking about a totally different product, is not cool..

That being said, the last time I asked for a F/W update (the G450H 20025 release is TRASH), I was told that the unit was no longer going to be updated as its EoL... SOOO Off to the Community Release's I went! (you lose the phone support or warranty if the firmware causes the unit to brick, but much better!)


RandyChev

Quote from: Net7 on April 10, 2014, 03:54:51 PM
Come on guy... Thread jacking, especially when talking about a totally different product, is not cool..

I've been posting on bulletin boards and forums since 1981 and this is the first time I've been accused of "thread jacking". Since it was the ONLY thread I could find discussing Heartbleed I suspected it was the proper place to discuss (gasp) Heartbleed on a Buffalo Product. (Oh, gee. "Heartbleed" and "Buffalo Product" are all in the thread subject... I must be in the wrong place.)

That being said...

Quote from: Net7 on April 10, 2014, 03:54:51 PM
That being said, the last time I asked for a F/W update (the G450H 20025 release is TRASH), I was told that the unit was no longer going to be updated as its EoL... SOOO Off to the Community Release's I went! (you lose the phone support or warranty if the firmware causes the unit to brick, but much better!)

Thank you for bringing me up to speed on my product being EOL. I bought this unit new just over a year ago so I had no idea it was near EOL. I'm quite happy with it and may look for another for backup. I will access my options and probably move to the community DD-WRT asap.

Sorry for intruding.

Eastmarch

A lot of that depends on what you are using DD-WRT for. Only VPN server and the web GUI use SSL, and web GUI has to be turned on to allow management through the WAN.
**A single copy of data, even on a RAID array, is NOT a backup! Hard drive failure is not a question of IF, but WHEN! Don't take my word for it, take Google's!**

Browser ID: smf (is_webkit)
Templates: 4: index (default), Display (default), GenericControls (default), GenericControls (default).
Sub templates: 6: init, html_above, body_above, main, body_below, html_below.
Language files: 5: index+Modifications.english (default), Post.english (default), Editor.english (default), Drafts.english (default), StopForumSpam.english (default).
Style sheets: 4: index.css, attachments.css, jquery.sceditor.css, responsive.css.
Hooks called: 229 (show)
Files included: 35 - 1354KB. (show)
Memory used: 1024KB.
Tokens: post-login.
Queries used: 16.

[Show Queries]