mlichvar pushed to ntp (f20). "4.2.6p5-21"
notifications at fedoraproject.org
notifications at fedoraproject.org
Wed Apr 8 12:01:22 UTC 2015
>From 8d45016292591c415b74ba1d19729973c6994ed3 Mon Sep 17 00:00:00 2001
From: Miroslav Lichvar <mlichvar at redhat.com>
Date: Wed, 8 Apr 2015 13:30:09 +0200
Subject: 4.2.6p5-21
diff --git a/ntp.spec b/ntp.spec
index 1e5fc42..8c42082 100644
--- a/ntp.spec
+++ b/ntp.spec
@@ -3,7 +3,7 @@
Summary: The NTP daemon and utilities
Name: ntp
Version: 4.2.6p5
-Release: 20%{?dist}
+Release: 21%{?dist}
# primary license (COPYRIGHT) : MIT
# ElectricFence/ (not used) : GPLv2
# kernel/sys/ppsclock.h (not used) : BSD with advertising
@@ -428,6 +428,11 @@ popd
%{ntpdocdir}/html
%changelog
+* Wed Apr 08 2015 Miroslav Lichvar <mlichvar at redhat.com> 4.2.6p5-21
+- reject packets without MAC when authentication is enabled (CVE-2015-1798)
+- protect symmetric associations with symmetric key against DoS attack
+ (CVE-2015-1799)
+
* Thu Feb 05 2015 Miroslav Lichvar <mlichvar at redhat.com> 4.2.6p5-20
- validate lengths of values in extension fields (CVE-2014-9297)
- drop packets with spoofed source address ::1 (CVE-2014-9298)
--
cgit v0.10.2
http://pkgs.fedoraproject.org/cgit/ntp.git/commit/?h=f20&id=8d45016292591c415b74ba1d19729973c6994ed3
More information about the scm-commits
mailing list