From: Harlan Stenn Date: Fri, 19 Dec 2014 06:36:35 +0000 (+0000) Subject: Merge bk://bk.ntp.org/ntp-dev X-Git-Tag: NTP_4_2_8~5 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=a3b9a84ceab66a873acdcb5db37b281699cfe8d8;p=thirdparty%2Fntp.git Merge bk://bk.ntp.org/ntp-dev into psp-deb1.ntp.org:/home/stenn/ntp-dev-sec bk: 5493c773H4LdXQL8D9B2AJUsVfw-pA --- a3b9a84ceab66a873acdcb5db37b281699cfe8d8 diff --cc ChangeLog index 825c7481f,df0121d7e..d02acebe5 --- a/ChangeLog +++ b/ChangeLog @@@ -1,10 -1,5 +1,14 @@@ ++--- ++ + * [Sec 730] Increase RSA_generate_key modulus. +* [Sec 2666] Use cryptographic random numbers for md5 key generation. +* [Sec 2667] buffer overflow in crypto_recv(). +* [Sec 2668] buffer overflow in ctl_putdata(). +* [Sec 2669] buffer overflow in configure(). +* [Sec 2670] Missing return; from error clause. +* [Sec 2671] vallen in extension fields are not validated. +* [Sec 2672] On some OSes ::1 can be spoofed, bypassing source IP ACLs. + * [Bug 2691] Wrong variable name in refclock_ripencc.c. (4.2.7p486-RC) 2014/12/18 Released by Harlan Stenn * [Bug 2687] RefClock 26/hpgps doesn't work at default line speed (4.2.7p485-RC) 2014/12/12 Released by Harlan Stenn