From: Harlan Stenn Date: Mon, 5 Oct 2015 11:26:22 +0000 (+0000) Subject: Merge psp-deb1.ntp.org:/home/stenn/ntp-stable-sec X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=b7c2b1033b500b73873ae730352d3602635874b2;p=thirdparty%2Fntp.git Merge psp-deb1.ntp.org:/home/stenn/ntp-stable-sec into psp-deb1.ntp.org:/home/perlinger/ntp-stable-cisco bk: 56125e5e0ZvV7oiclOBsXLECRxsesA --- b7c2b1033b500b73873ae730352d3602635874b2 diff --cc ChangeLog index 9c7390af2,31cffecc9..598363134 --- a/ChangeLog +++ b/ChangeLog @@@ -1,11 -1,7 +1,14 @@@ --- -* [TALOS-CAN-0052] crash by loop counter underrun. perlinger@ntp.org -* [TALOS-CAN-0054] memory corruption in password store. perlinger@ntp.org -* [TALOS-CAN-0063] avoid buffer overrun in ntpq. perlinger@ntp.org +* [Sec 2899] CVE-2014-9297 perlinger@ntp.org +* [Sec 2902] configuration directives "pidfile" and "driftfile" + should be local-only. perlinger@ntp.org (patch by Miroslav Lichvar) +* [Sec 2909] added missing call to 'free()' in ntp_crypto.c. perlinger@ntp.org ++* [Sec 2913] TALOS-CAN-0052: crash by loop counter underrun. perlinger@ntp.org ++* [Sec 2916] TALOS-CAN-0054: memory corruption in password store. JPerlinger ++* [Bug 2919] TALOS-CAN-0063: avoid buffer overrun in ntpq. perlinger@ntp.org +* [Bug 2332] (reopened) Exercise thread cancellation once before dropping + privileges and limiting resources in NTPD removes the need to link + forcefully against 'libgcc_s' which does not always work. J.Perlinger * [Bug 2595] ntpdate man page quirks. Hal Murray, Harlan Stenn. * [Bug 2625] Deprecate flag1 in local refclock. Hal Murray, Harlan Stenn. * [Bug 2817] Stop locking ntpd into memory by default under Linux. H.Stenn.