• February 22, 2025, 02:39:14 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: FW 1.04 Build 11 Back on US Site  (Read 11632 times)

jclarkw

  • Level 2 Member
  • **
  • Posts: 93
FW 1.04 Build 11 Back on US Site
« on: December 18, 2013, 10:48:21 AM »

I notice that D-Link has finally replaced FW 1.04B11 on their support site (DIR-645, all HW versions, NA region), dated 12/4/13.  The .BIN file itself is dated 6/14/13, however, and appears identical to the one previously available through this forum.  There are currently no updated release notes since B10 on the support site, so it isn't clear exactly how B11 differs from B10.  Anyhow I guess it's once again an official release...

The earlier thread announcing release of 1.04B11 seems to have disappeared along with the link to the vulnerability that it may have addressed (I can't find that anymore).  Does anybody know if this build actually fixes that vulnerability?  Are there other important reasons for flashing it on top of B10? -- jclarkw
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: FW 1.04 Build 11 Back on US Site
« Reply #1 on: December 18, 2013, 11:59:39 AM »

Thank you for letting us know.

I'll post it when I get official information regarding it. Please be patient.

http://forums.dlink.com/index.php?topic=56969.0
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: FW 1.04 Build 11 Back on US Site
« Reply #2 on: December 19, 2013, 12:06:08 PM »

Ok, information forth coming soon and should be posted on the main site soon.

Also, got word that the 645 is now headed to EOL.  :'(
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: FW 1.04 Build 11 Back on US Site
« Reply #3 on: December 19, 2013, 02:08:31 PM »

Release notes updated.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

jclarkw

  • Level 2 Member
  • **
  • Posts: 93
Re: FW 1.04 Build 11 Back on US Site
« Reply #4 on: December 19, 2013, 03:40:18 PM »

Logged

jclarkw

  • Level 2 Member
  • **
  • Posts: 93
Re: FW 1.04 Build 11 Back on US Site
« Reply #5 on: December 19, 2013, 06:00:44 PM »

Release notes updated.


Interesting:  The only vulnerabilities listed in these release notes that were not already listed in the previous release notes for Build 10 (dated 06/11/2013) are the three fixes for "Buffer overflow" and the three for "(CSRF)."

I don't see the "Michael Messner/D-Link UPnP OS Command Injection" vulnerability listed even though Build 11 supposedly fixes it -- see http://www.exploit-download.com/search/cgi/96.  Another vulnerability reported fixed in the same site but not listed in the release is "m-1-k-3/Multiple D-Link Devices - OS-Command Injection via UPnP Interface"..  (I don't allow UPnP, so this isn't really an issue for me.)

Of potentially more concern (apparently -- I don't really understand the jargon) is the statement, also on the same site, "D-Link devices DIR-300 rev B, DIR-600 rev B, DIR-645, DIR-845, and DIR-865 suffer from a remote command injection vulnerability. The vulnerability is caused due to missing input validation in different XML parameters."  This is not reported as fixed, as far as I can tell.

There's another reference at http://www.osvdb.org/show/osvdb/94924 that might be describing one or more of the above and reports that Build 11 solves the problem.

Anyhow it appears worthwhile to flash the new build.  Agreed?  Or can you help clarify the issues?
« Last Edit: December 19, 2013, 07:10:00 PM by jclarkw »
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: FW 1.04 Build 11 Back on US Site
« Reply #6 on: December 20, 2013, 07:29:49 AM »

I'd go with upgrading man. Unless your really having troubles with what is listed in the notes, upgrading and have some peace of mind. I personally haven't experienced issues with this router other what what you have found and brought to our attention, and during its life time and I think it's still a great router. Sorry to see it go into EOL. From my understanding, unless there is any more critical issues found, no more FW will be forth coming.  :-\


Enjoy.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

jclarkw

  • Level 2 Member
  • **
  • Posts: 93
Re: FW 1.04 Build 11 Back on US Site
« Reply #7 on: December 20, 2013, 01:46:27 PM »

...I personally haven't experienced issues with this router other what what you have found and brought to our attention, and during its life time and I think it's still a great router...


Thanks!  Maybe I'll buy another before they disappear (still available "fulfilled by" Amazon, and cheap).  I have a very old Netgear router at another location... -- jclarkw
« Last Edit: December 20, 2013, 01:52:24 PM by jclarkw »
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: FW 1.04 Build 11 Back on US Site
« Reply #8 on: December 20, 2013, 02:36:23 PM »

 ;) Good little routers. I've enjoyed mine...
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.