Jump to content

Firmware release notes 4.7.7

From SpinetiX Wiki
Release name: "Grand Pilier d'Angle" 4.7.7. Release date: June 13th, 2023.
Applies to HMP400, HMP400W, HMP350, HMP300, DiVA, and third-party players.
Firmware version number: 4.7.7-1.0.1-275a322e
Note Note:
For other versions, see the DSOS release notes page.

Improvements

Applies to HMP400, HMP400W, and third-party players

Fixes

  • Control Center used low quality pseudo-random number generator in some cases, although they were not used for creating sensitive secrets; now all generated pseudo-random data comes from a cryptographically secure generator.
  • Incomplete error handling in Control Center could leave temporary directories, and files within, behind; they are not properly removed when the operation completes, even in case of error.
  • The firmware update component could incorrectly report and apply minor component updates when the update source (e.g., USB stick) was for a firmware version lower than already installed.


Applies to HMP400, HMP400W, and third-party players

  • Video-in capture was no longer working, this was a regression introduced in firmware 4.7.6.
  • Restoring a configuration backup could sometimes fail with a "file extraction of config failed".
  • The Wi-Fi configuration wizard would not allow to manually enter a network name (i.e., SSID) if there were no visible networks in range.
  • Connecting to a network from the Wi-Fi configuration wizard could fail with a "Connection failed, check password" error, even if the password was correct, in particular if the network is hidden.

Security

Updated base libraries and components, the main changes are as follows.

  • apache2: updated to version 2.4.56, fixing CVE-2023-25690, CVE-2006-20001, CVE-2022-37436 and CVE-2022-28614, all of which affected the firmware, and CVE-2023-27522, CVE-2022-36760, CVE-2022-26377, CVE-2022-28330, CVE-2022-28615, CVE-2022-29404, CVE-2022-30522, CVE-2022-30556 and CVE-2022-31813, none of which affected the firmware.
  • apr: updated to version 1.7.2, fixing CVE-2022-24963 and CVE-2021-35940, both of which affected the firmware, and CVE-2022-28331, which did not affect the firmware.
  • apr-util: updated to version 1.6.3, fixing CVE-2022-25147, which affected the firmware.
  • curl: fixed CVE-2022-32221, which affected the firmware, and CVE-2022-35260 and CVE-2022-43552, none of which affected the firmware.
  • expat: fixed CVE-2022-43680, which affected the firmware.
  • glibc: fixed CVE-2021-3999, which affected the firmware, and CVE-2023-0687, which did not affect the firmware.
  • grub2: fixed CVE-2022-28735, which may have affected the firmware, and CVE-2022-2601 and CVE-2022-3775, none of which affected the firmware.
  • gnutls: fixed CVE-2023-0361, which affected the firmware.
  • gstreamer: updated to version 1.18.4, fixing CVE-2021-3497, CVE-2021-3498 and CVE-2021-3522, all of which affected the firmware.
  • harfbuzz: fixed CVE-2023-25193, which affected the firmware.
  • libarchive: fixed CVE-2022-36227, which affected the firmware.
  • libtasn1: fixed CVE-2021-46848, which affected the firmware.
  • libxml2: fixed CVE-2022-40304 and CVE-2022-40303, both of which affected the firmware.
  • net-snmp: fixed CVE-2022-44792 and CVE-2022-44793, both of which affected the firmware.
  • openssl: updated to version 1.1.1t, fixing CVE-2023-0286, CVE-2023-0215, CVE-2022-4450, CVE-2022-4304, all of which affected the firmware.
  • php: updated to version 7.4.33, fixing CVE-2022-31628, CVE-2022-31629 and CVE-2022-31630, all of which affected the firmware, and CVE-2022-31625, CVE-2022-31626, and CVE-2022-37454, none of which affected the firmware.
  • rpm: fixed CVE-2021-3521, which did not affect the firmware.
  • tar: fixed CVE-2022-48303, which did not affect the firmware.
  • tzdata: updated to version 2022g.


Applies to HMP400, HMP400W, and third-party players

  • bluez: fixed CVE-2022-3637, which was unlikely to affect the firmware.
  • dnsmasq: fixed CVE-2023-28450, which affected the firmware.
  • linux-firmware: updated to version 20230210.
  • linux-microcode: updated to version 20230214, fixing CVE-2022-38090 which may have affected some third part players running DSOS, and CVE-2022-33196 and CVE-2022-21216, none of which affected players compatible with DSOS.
  • Linux kernel updated to version 5.4.209, fixing the following security issues:
    • That did affect the firmware: CVE-2022-1729, CVE-2022-21499, CVE-2022-1184, CVE-2022-21125, CVE-2022-21166, CVE-2022-21123, CVE-2022-32296, CVE-2021-33656, CVE-2023-2008, CVE-2021-33655, CVE-2022-36123, CVE-2022-1462 and CVE-2022-20566.
    • That did not affect the firmware: CVE-2022-28893, CVE-2022-1652, CVE-2023-1838, CVE-2022-20572, CVE-2022-2503, CVE-2022-1012, CVE-2022-1966, CVE-2022-32981, CVE-2022-3577, CVE-2022-32250, CVE-2022-3115, CVE-2022-2318, CVE-2022-33742, CVE-2022-33741, CVE-2022-33740, CVE-2022-26365, CVE-2022-33744, CVE-2022-21505, CVE-2022-36879, CVE-2022-36946 and CVE-2023-2177.
  • nss: fixed CVE-2020-25648 and CVE-2023-0767, both of which affected the firmware.
  • pixman: fixed CVE-2022-44638, which affected the firmware.
  • wireless-regdb: updated to version 2023.02.13.
We use only essential cookies for site functionality.