From: Harlan Stenn Date: Thu, 21 Jan 2016 07:35:48 +0000 (+0000) Subject: merge cleanup X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=6b7cf933d4644949c3facb465b9901f441ebf1dd;p=thirdparty%2Fntp.git merge cleanup bk: 56a08a54uADhHcutojDiGC0sQEhtCQ --- diff --git a/ChangeLog b/ChangeLog index 179123824..9458ee18d 100644 --- a/ChangeLog +++ b/ChangeLog @@ -1,4 +1,10 @@ --- + +* [Bug 2879] Improve NTP security against timing attacks. perlinger@ntp.org + - integrated patches by Loganaden Velvidron + with some modifications & unit tests + +--- (4.2.8p6) 2016/01/20 Released by Harlan Stenn * [Sec 2935] Deja Vu: Replay attack on authenticated broadcast mode. HStenn. @@ -53,9 +59,6 @@ * CID 1341682: Nit in libntp/authreadkeys.c. HStenn. * CID 1341684: Nit in tests/ntpd/t-ntp_signd.c. HStenn. * [Bug 2829] Look at pipe_fds in ntpd.c (did so. perlinger@ntp.org) -* [Bug 2879] Improve NTP security against timing attacks. perlinger@ntp.org - - integrated patches by Loganaden Velvidron - with some modifications & unit tests * [Bug 2887] stratum -1 config results as showing value 99 - fudge stratum should only accept values [0..16]. perlinger@ntp.org * [Bug 2932] Update leapsecond file info in miscopt.html. CWoodbury, HStenn. @@ -95,6 +98,7 @@ * Update scripts/calc_tickadj/Makefile.am. Harlan Stenn. --- +(4.2.8p4) 2015/10/21 Released by Harlan Stenn * [Sec 2899] CVE-2014-9297 perlinger@ntp.org * [Sec 2901] Drop invalid packet before checking KoD. Check for all KoD's.