From feda697c8411a581bacf517fa956a4e8d9b3682b Mon Sep 17 00:00:00 2001 From: Miroslav Lichvar Date: Mar 23 2017 15:08:08 +0000 Subject: 4.2.6p5-44 --- diff --git a/ntp.spec b/ntp.spec index 495e850..f22f3cf 100644 --- a/ntp.spec +++ b/ntp.spec @@ -3,7 +3,7 @@ Summary: The NTP daemon and utilities Name: ntp Version: 4.2.6p5 -Release: 43%{?dist} +Release: 44%{?dist} # primary license (COPYRIGHT) : MIT # ElectricFence/ (not used) : GPLv2 # kernel/sys/ppsclock.h (not used) : BSD with advertising @@ -606,6 +606,16 @@ popd %{ntpdocdir}/html %changelog +* Thu Mar 23 2017 Miroslav Lichvar 4.2.6p5-44 +- fix crash with invalid unpeer command (CVE-2017-6463) +- fix buffer overflow in datum refclock driver (CVE-2017-6462) +- fix potential buffer overflow in mx4200 refclock driver (CVE-2017-6451) +- fix potential buffer overflows in formatting of ntpq responses + (CVE-2017-6458) +- fix potential crash with invalid server command (CVE-2017-6464) +- fix CVE-2016-7429 patch to work correctly on multicast client +- fix typos in ntpd man page (#1434755) + * Tue Nov 22 2016 Miroslav Lichvar 4.2.6p5-43 - don't limit rate of packets from sources (CVE-2016-7426) - don't change interface from received packets (CVE-2016-7429)