-------------------------------------------------------------------------------- Fedora EPEL Update Notification FEDORA-EPEL-2013-11195 2013-08-16 15:52:29 --------------------------------------------------------------------------------
Name : chrony Product : Fedora EPEL 6 Version : 1.25 Release : 3.el6 URL : http://chrony.tuxfamily.org Summary : An NTP client/server Description : A client/server for the Network Time Protocol, this program keeps your computer's clock accurate. It was specially designed to support systems with intermittent internet connections, but it also works well in permanently connected environments. It can use also hardware reference clocks, system real-time clock or manual input as time references.
-------------------------------------------------------------------------------- Update Information:
This update fixes two security vulnerabilities: a crash when processing crafted commands (CVE-2012-4502) and uninitialized data sent in command replies (CVE-2012-4503). -------------------------------------------------------------------------------- References:
[ 1 ] Bug #846392 - CVE-2012-4502 CVE-2012-4503 chrony: Two security flaws fixed in chrony-1.29 release https://bugzilla.redhat.com/show_bug.cgi?id=846392 --------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use su -c 'yum update chrony' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------
epel-package-announce@lists.fedoraproject.org