mlichvar pushed to ntp (f21). "fix crash in ntpq mreadvar command"

notifications at fedoraproject.org notifications at fedoraproject.org
Wed Apr 8 11:46:45 UTC 2015


>From 062ff0922b2815cb2d6f0c000f504ddbed13d7f0 Mon Sep 17 00:00:00 2001
From: Miroslav Lichvar <mlichvar at redhat.com>
Date: Thu, 26 Feb 2015 15:32:55 +0100
Subject: fix crash in ntpq mreadvar command


diff --git a/ntp-4.2.6p5-mreadvar.patch b/ntp-4.2.6p5-mreadvar.patch
new file mode 100644
index 0000000..ed9dffc
--- /dev/null
+++ b/ntp-4.2.6p5-mreadvar.patch
@@ -0,0 +1,13 @@
+diff -up ntp-4.2.6p5/ntpq/ntpq-subs.c.mreadvar ntp-4.2.6p5/ntpq/ntpq-subs.c
+--- ntp-4.2.6p5/ntpq/ntpq-subs.c.mreadvar	2011-12-25 00:27:15.000000000 +0100
++++ ntp-4.2.6p5/ntpq/ntpq-subs.c	2015-02-09 12:13:02.215449708 +0100
+@@ -857,8 +857,8 @@ mreadvar(
+ 				&from, &to))
+ 		return;
+ 
++	memset(tmplist, 0, sizeof(tmplist));
+ 	if (pcmd->nargs >= 3) {
+-		memset(tmplist, 0, sizeof(tmplist));
+ 		doaddvlist(tmplist, pcmd->argval[2].string);
+ 		pvars = tmplist;
+ 	} else {
diff --git a/ntp.spec b/ntp.spec
index 90833cc..2c63080 100644
--- a/ntp.spec
+++ b/ntp.spec
@@ -109,6 +109,8 @@ Patch28: ntp-4.2.6p5-cve-2014-9297.patch
 Patch29: ntp-4.2.6p5-cve-2014-9298.patch
 # ntpbz #2174
 Patch30: ntp-4.2.6p5-sourceport.patch
+# ntpbz #2661
+Patch31: ntp-4.2.6p5-mreadvar.patch
 
 # handle unknown clock types
 Patch50: ntpstat-0.2-clksrc.patch
@@ -232,6 +234,7 @@ This package contains NTP documentation in HTML format.
 %patch28 -p1 -b .cve-2014-9297
 %patch29 -p1 -b .cve-2014-9298
 %patch30 -p1 -b .sourceport
+%patch31 -p1 -b .mreadvar
 
 # ntpstat patches
 %patch50 -p1 -b .clksrc
-- 
cgit v0.10.2


	http://pkgs.fedoraproject.org/cgit/ntp.git/commit/?h=f21&id=062ff0922b2815cb2d6f0c000f504ddbed13d7f0


More information about the scm-commits mailing list