-
ntp (1:4.2.4p4+dfsg-6ubuntu2.4) intrepid-security; urgency=low
* SECURITY UPDATE: fix DoS with mode 7 (MODE_PRIVATE) packets
- debian/patches/CVE-2009-3563.patch: update ntpd/ntp_request.c to
not send a response packet for and rate limit logging of invalid mode 7
requests and responses
- CVE-2009-3563
-- Jamie Strandboge <email address hidden> Thu, 03 Dec 2009 14:28:25 -0600
-
ntp (1:4.2.4p4+dfsg-6ubuntu2.3) intrepid-security; urgency=low
* SECURITY UPDATE: stack overflow in ntpd when autokey is enabled
- debian/patches/CVE-2009-1252.patch: update ntpd/ntp_crypto.c to use
snprintf() with NTP_MAXSTRLEN when writing to statstr. Also defensively
adjust ntp_peer.c and ntp_timer.c to do the same.
- CVE-2009-1252
* SECURITY UPDATE: stack overflow in ntpq when contacting malicious ntp
server
- debian/patches/CVE-2009-0159.patch: increase size of buffer in
cookedprint() in ntpq/ntpq.c and adjust to use snprintf()
- CVE-2009-0159
-- Jamie Strandboge <email address hidden> Wed, 13 May 2009 12:40:32 -0500
-
ntp (1:4.2.4p4+dfsg-6ubuntu2.2) intrepid-security; urgency=low
* SECURITY UPDATE: clients treat malformed signatures as good when verifying
server DSA and ECDSA certificates.
- debian/patches/CVE-2009-0021.patch: update ntpd/ntp_crypto.c to properly
check the return code of EVP_VerifyFinal()
- CVE-2009-0021
-- Jamie Strandboge <email address hidden> Tue, 06 Jan 2009 01:27:10 -0600
-
ntp (1:4.2.4p4+dfsg-6ubuntu2.1) intrepid-proposed; urgency=low
* Add ipv6-gnu-source.patch: Define _GNU_SOURCE to make IPv6 work.
(LP: #305043)
-- Matt LaPlante <email address hidden> Tue, 09 Dec 2008 10:29:30 -0800
-
ntp (1:4.2.4p4+dfsg-6ubuntu2) intrepid; urgency=low
* debian/ntpdate.ifup: use a different lockfile to avoid dead-locks
when restarting ntpd (LP: #246203).
-- Kees Cook <email address hidden> Wed, 20 Aug 2008 09:48:33 -0700
-
ntp (1:4.2.4p4+dfsg-6ubuntu1) intrepid; urgency=low
* Merge from debian unstable, remaining changes:
- debian/ntp.conf, debian/ntpdate.default:
- Change default server to ntp.ubuntu.com.
- debian/control:
- Set Ubuntu maintainer address.
- debian/ntpdate.ifup:
Stop ntp before running ntpdate when an interface
comes up, then start again afterwards (LP: #114505)
* debian/rules:
- Call update-rcd-params with manual arguments instead of defaults.
* debian/ntp.init:
- Update LSB Default-Stop header.
* Dropped:
- Update TearDown spec implementation:
- Update version in conflicts/replaces to that which was shipped in
edgy, which was later than that in Debian (due to the ubuntuX).
- Add sysv-rc dependency.
- debian/rules:
- Call update-rcd-params with multiuser instead defaults.
- debian/ntp-server.postinst (dapper upgrade):
- Remove stop script symlinks from rc0 and rc6.
ntp (1:4.2.4p4+dfsg-6) unstable; urgency=low
* Put back accidentally removed /etc/defaults/ntpdate (closes: #482605)
* Updated Homepage (closes: #482628)
* Use libedit instead of libreadline, added libedit.patch (closes: #448408)
* While updating autotools.patch, added description how it is generated
(closes: #446756)
* Since the scripts summary and plot_summary are not installed in a binary
package, drop their mention from the copyright file, thus deconfusing
lintian
* Avoid timeout message from ntpdate.if-up when ntpdate package was removed
but not purged (closes: #481049)
ntp (1:4.2.4p4+dfsg-5) unstable; urgency=low
* Removed mentions of -d and -D options from ntpd man page, because the
Debian package does not support these options (closes: #479015)
* Ignore errors from ntpdate-debian call in ntpdate.if-up (closes: #478655)
ntp (1:4.2.4p4+dfsg-4) unstable; urgency=low
* Small ntp.conf man page fix (patch by Justin Pryzby) (closes: #450721)
* Removed incorrect mention of -m option on ntpd man page (closes: #468348)
* Corrected doc-base section for ntp-doc
* Added build conflicts against libavahi-compat-libdnssd-dev, so that that
feature isn't accidentally enabled (closes: #462597)
* Added build conflicts against libwww-dev, libwww-ssl-dev, so we don't
accidentally link with their libmd5 (closes: #462597)
* Use lockfile-progs to ensure that only one ntpdate.ifup is running at a
time (closes: #471358)
* Also use lockfile-progs to ensure that ntpd does not start while
ntpdate.ifup is running (closes: #436029)
* Updated ntp.conf man page from HTML (closes: #466046)
* Changed control fields XS-Vcs-* to Vcs-*, and added trunk path
* Removed code used for sarge to etch transition
* Changed to Debhelper level 6
* Use dh_installifupdown
* Removed tickadj program from installation. It is quite unportable, the
documentation is inaccurate, and adjtimex could be used instead.
-- Mathias Gug <email address hidden> Wed, 18 Jun 2008 22:28:16 -0400
-
ntp (1:4.2.4p4+dfsg-3ubuntu2) hardy; urgency=low
* Stop ntp before running ntpdate when an interface
comes up, then start again afterwards (LP: #114505)
-- Onno Benschop <email address hidden> Thu, 6 Mar 2008 14:00:42 +0900