Firmware release notes 4.7.7
Appearance
Release name: "Grand Pilier d'Angle" 4.7.7. Release date: June 13th, 2023.
For other versions, see the DSOS release notes page.
Improvements
Applies to HMP400, HMP400W, and third-party players
- Control Center now shows the status (e.g., configured, authenticated) of 802.1X on the Ethernet interface in the Network settings page.
Fixes
- Control Center used low quality pseudo-random number generator in some cases, although they were not used for creating sensitive secrets; now all generated pseudo-random data comes from a cryptographically secure generator.
- Incomplete error handling in Control Center could leave temporary directories, and files within, behind; they are not properly removed when the operation completes, even in case of error.
- The firmware update component could incorrectly report and apply minor component updates when the update source (e.g., USB stick) was for a firmware version lower than already installed.
Applies to HMP400, HMP400W, and third-party players
- Video-in capture was no longer working, this was a regression introduced in firmware 4.7.6.
- Restoring a configuration backup could sometimes fail with a "file extraction of config failed".
- The Wi-Fi configuration wizard would not allow to manually enter a network name (i.e., SSID) if there were no visible networks in range.
- Connecting to a network from the Wi-Fi configuration wizard could fail with a "Connection failed, check password" error, even if the password was correct, in particular if the network is hidden.
Security
Updated base libraries and components, the main changes are as follows.
- apache2: updated to version 2.4.56, fixing CVE-2023-25690, CVE-2006-20001, CVE-2022-37436 and CVE-2022-28614, all of which affected the firmware, and CVE-2023-27522, CVE-2022-36760, CVE-2022-26377, CVE-2022-28330, CVE-2022-28615, CVE-2022-29404, CVE-2022-30522, CVE-2022-30556 and CVE-2022-31813, none of which affected the firmware.
- apr: updated to version 1.7.2, fixing CVE-2022-24963 and CVE-2021-35940, both of which affected the firmware, and CVE-2022-28331, which did not affect the firmware.
- apr-util: updated to version 1.6.3, fixing CVE-2022-25147, which affected the firmware.
- curl: fixed CVE-2022-32221, which affected the firmware, and CVE-2022-35260 and CVE-2022-43552, none of which affected the firmware.
- expat: fixed CVE-2022-43680, which affected the firmware.
- glibc: fixed CVE-2021-3999, which affected the firmware, and CVE-2023-0687, which did not affect the firmware.
- grub2: fixed CVE-2022-28735, which may have affected the firmware, and CVE-2022-2601 and CVE-2022-3775, none of which affected the firmware.
- gnutls: fixed CVE-2023-0361, which affected the firmware.
- gstreamer: updated to version 1.18.4, fixing CVE-2021-3497, CVE-2021-3498 and CVE-2021-3522, all of which affected the firmware.
- harfbuzz: fixed CVE-2023-25193, which affected the firmware.
- libarchive: fixed CVE-2022-36227, which affected the firmware.
- libtasn1: fixed CVE-2021-46848, which affected the firmware.
- libxml2: fixed CVE-2022-40304 and CVE-2022-40303, both of which affected the firmware.
- net-snmp: fixed CVE-2022-44792 and CVE-2022-44793, both of which affected the firmware.
- openssl: updated to version 1.1.1t, fixing CVE-2023-0286, CVE-2023-0215, CVE-2022-4450, CVE-2022-4304, all of which affected the firmware.
- php: updated to version 7.4.33, fixing CVE-2022-31628, CVE-2022-31629 and CVE-2022-31630, all of which affected the firmware, and CVE-2022-31625, CVE-2022-31626, and CVE-2022-37454, none of which affected the firmware.
- rpm: fixed CVE-2021-3521, which did not affect the firmware.
- tar: fixed CVE-2022-48303, which did not affect the firmware.
- tzdata: updated to version 2022g.
Applies to HMP400, HMP400W, and third-party players
- bluez: fixed CVE-2022-3637, which was unlikely to affect the firmware.
- dnsmasq: fixed CVE-2023-28450, which affected the firmware.
- linux-firmware: updated to version 20230210.
- linux-microcode: updated to version 20230214, fixing CVE-2022-38090 which may have affected some third part players running DSOS, and CVE-2022-33196 and CVE-2022-21216, none of which affected players compatible with DSOS.
- Linux kernel updated to version 5.4.209, fixing the following security issues:
- That did affect the firmware: CVE-2022-1729, CVE-2022-21499, CVE-2022-1184, CVE-2022-21125, CVE-2022-21166, CVE-2022-21123, CVE-2022-32296, CVE-2021-33656, CVE-2023-2008, CVE-2021-33655, CVE-2022-36123, CVE-2022-1462 and CVE-2022-20566.
- That did not affect the firmware: CVE-2022-28893, CVE-2022-1652, CVE-2023-1838, CVE-2022-20572, CVE-2022-2503, CVE-2022-1012, CVE-2022-1966, CVE-2022-32981, CVE-2022-3577, CVE-2022-32250, CVE-2022-3115, CVE-2022-2318, CVE-2022-33742, CVE-2022-33741, CVE-2022-33740, CVE-2022-26365, CVE-2022-33744, CVE-2022-21505, CVE-2022-36879, CVE-2022-36946 and CVE-2023-2177.
- nss: fixed CVE-2020-25648 and CVE-2023-0767, both of which affected the firmware.
- pixman: fixed CVE-2022-44638, which affected the firmware.
- wireless-regdb: updated to version 2023.02.13.