~ubuntu-branches/ubuntu/maverick/ntp/maverick-proposed

« back to all changes in this revision

Viewing changes to debian/patches/series

  • Committer: Bazaar Package Importer
  • Author(s): Jamie Strandboge
  • Date: 2009-05-19 15:26:41 UTC
  • Revision ID: james.westby@ubuntu.com-20090519152641-ctb02x7tfqv5e9a8
Tags: 1:4.2.4p6+dfsg-1ubuntu2
* SECURITY UPDATE: stack overflow in ntpd when autokey is enabled
  - debian/patches/CVE-2009-1252.patch: update ntpd/ntp_crypto.c to use
    snprintf() with NTP_MAXSTRLEN when writing to statstr. Also defensively
    adjust ntp_peer.c and ntp_timer.c to do the same.
  - CVE-2009-1252
* SECURITY UPDATE: stack overflow in ntpq when contacting malicious ntp
  server
  - debian/patches/CVE-2009-0159.patch: increase size of buffer in
    cookedprint() in ntpq/ntpq.c and adjust to use snprintf()
  - CVE-2009-0159

Show diffs side-by-side

added added

removed removed

Lines of Context:
10
10
openssl-disable-check.patch
11
11
libedit.patch
12
12
autotools.patch
 
13
CVE-2009-1252.patch
 
14
CVE-2009-0159.patch