From: Harlan Stenn Date: Thu, 18 Dec 2014 06:09:05 +0000 (+0000) Subject: Merge bk://bk.ntp.org/ntp-dev X-Git-Tag: NTP_4_2_8~10 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=95ab075ebdd6a38509e7ab0ba0683e3c736512cd;p=thirdparty%2Fntp.git Merge bk://bk.ntp.org/ntp-dev into psp-deb1.ntp.org:/home/stenn/ntp-dev-sec bk: 54926f81l4wj7rTE7rxqXSc5iP9mNA --- 95ab075ebdd6a38509e7ab0ba0683e3c736512cd diff --cc ChangeLog index de193864c,43294236a..ef9ccdb90 --- a/ChangeLog +++ b/ChangeLog @@@ -1,9 -1,4 +1,10 @@@ +* [Sec 2666] Use cryptographic random numbers for md5 key generation. +* [Sec 2667] buffer overflow in crypto_recv(). +* [Sec 2668] buffer overflow in ctl_putdata(). +* [Sec 2669] buffer overflow in configure(). +* [Sec 2670] Missing return; from error clause. +* [Sec 2672] On some OSes ::1 can be spoofed, bypassing source IP ACLs. + * [Bug 2687] RefClock 26/hpgps doesn't work at default line speed (4.2.7p485-RC) 2014/12/12 Released by Harlan Stenn * [Bug 2686] refclock_gpsdjson needs strtoll(), which is not always present. (4.2.7p484-RC) 2014/12/11 Released by Harlan Stenn