[ubuntu/hardy-security] chrony (delayed), chrony 1.21z-5+etch1build0.8.04.1 (Accepted)

Ubuntu Installer archive at ubuntu.com
Wed Feb 17 18:06:15 GMT 2010


chrony (1.21z-5+etch1build0.8.04.1) hardy-security; urgency=low

  * fake sync from Debian

chrony (1.21z-5+etch1) oldstable-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * This update addresses the following security issues:
    - CVE-2010-0292: chronyd replies to all cmdmon packets from unauthorized
      hosts with.
    - CVE-2010-0293: missing memory limit for to keep client information which
      can lead to memory exhaustion through clients with spoofed IPs
    - CVE-2010-0294: missing syslog limit could lead to filling up the disc
      by triggering various log events in a loop.

Date: Fri, 12 Feb 2010 12:29:55 -0600
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Maintainer: John Hasler <jhasler at debian.org>
https://launchpad.net/ubuntu/hardy/+source/chrony/1.21z-5+etch1build0.8.04.1
-------------- next part --------------
Format: 1.7
Date: Fri, 12 Feb 2010 12:29:55 -0600
Source: chrony
Binary: chrony
Architecture: source
Version: 1.21z-5+etch1build0.8.04.1
Distribution: hardy-security
Urgency: high
Maintainer: John Hasler <jhasler at debian.org>
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Description: 
 chrony     - Sets your computer's clock from time servers on the Net
Changes: 
 chrony (1.21z-5+etch1build0.8.04.1) hardy-security; urgency=low
 .
   * fake sync from Debian
 .
 chrony (1.21z-5+etch1) oldstable-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * This update addresses the following security issues:
     - CVE-2010-0292: chronyd replies to all cmdmon packets from unauthorized
       hosts with.
     - CVE-2010-0293: missing memory limit for to keep client information which
       can lead to memory exhaustion through clients with spoofed IPs
     - CVE-2010-0294: missing syslog limit could lead to filling up the disc
       by triggering various log events in a loop.
Files: 
 8613d3f193860e35691ae2b1612fec14 655 admin extra chrony_1.21z-5+etch1build0.8.04.1.dsc
 db0b98b3233204803f4da77dea2b9748 158362 admin extra chrony_1.21z-5+etch1build0.8.04.1.diff.gz


More information about the Hardy-changes mailing list