From: Harlan Stenn Date: Thu, 18 Dec 2014 10:06:22 +0000 (+0000) Subject: Merge bk://bk.ntp.org/ntp-dev X-Git-Tag: NTP_4_2_8~9 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=c9ca5ded493a5452df353b7dff8ae8fcbb83b838;p=thirdparty%2Fntp.git Merge bk://bk.ntp.org/ntp-dev into psp-deb1.ntp.org:/home/stenn/ntp-dev-sec bk: 5492a71e1ouvIMvhfK8OeW-hM79FcA --- c9ca5ded493a5452df353b7dff8ae8fcbb83b838 diff --cc ChangeLog index ef9ccdb90,a6680c32e..3e4b51827 --- a/ChangeLog +++ b/ChangeLog @@@ -1,9 -1,4 +1,10 @@@ +* [Sec 2666] Use cryptographic random numbers for md5 key generation. +* [Sec 2667] buffer overflow in crypto_recv(). +* [Sec 2668] buffer overflow in ctl_putdata(). +* [Sec 2669] buffer overflow in configure(). +* [Sec 2670] Missing return; from error clause. +* [Sec 2672] On some OSes ::1 can be spoofed, bypassing source IP ACLs. + (4.2.7p486-RC) 2014/12/18 Released by Harlan Stenn * [Bug 2687] RefClock 26/hpgps doesn't work at default line speed (4.2.7p485-RC) 2014/12/12 Released by Harlan Stenn * [Bug 2686] refclock_gpsdjson needs strtoll(), which is not always present.