mlichvar pushed to ntp (f20). "4.2.6p5-21"

notifications at fedoraproject.org notifications at fedoraproject.org
Wed Apr 8 12:01:22 UTC 2015


>From 8d45016292591c415b74ba1d19729973c6994ed3 Mon Sep 17 00:00:00 2001
From: Miroslav Lichvar <mlichvar at redhat.com>
Date: Wed, 8 Apr 2015 13:30:09 +0200
Subject: 4.2.6p5-21


diff --git a/ntp.spec b/ntp.spec
index 1e5fc42..8c42082 100644
--- a/ntp.spec
+++ b/ntp.spec
@@ -3,7 +3,7 @@
 Summary: The NTP daemon and utilities
 Name: ntp
 Version: 4.2.6p5
-Release: 20%{?dist}
+Release: 21%{?dist}
 # primary license (COPYRIGHT) : MIT
 # ElectricFence/ (not used) : GPLv2
 # kernel/sys/ppsclock.h (not used) : BSD with advertising
@@ -428,6 +428,11 @@ popd
 %{ntpdocdir}/html
 
 %changelog
+* Wed Apr 08 2015 Miroslav Lichvar <mlichvar at redhat.com> 4.2.6p5-21
+- reject packets without MAC when authentication is enabled (CVE-2015-1798)
+- protect symmetric associations with symmetric key against DoS attack
+  (CVE-2015-1799)
+
 * Thu Feb 05 2015 Miroslav Lichvar <mlichvar at redhat.com> 4.2.6p5-20
 - validate lengths of values in extension fields (CVE-2014-9297)
 - drop packets with spoofed source address ::1 (CVE-2014-9298)
-- 
cgit v0.10.2


	http://pkgs.fedoraproject.org/cgit/ntp.git/commit/?h=f20&id=8d45016292591c415b74ba1d19729973c6994ed3


More information about the scm-commits mailing list