[ubuntu/vivid-proposed] ntp 1:4.2.6.p5+dfsg-3ubuntu5 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Wed Apr 8 08:52:20 UTC 2015


ntp (1:4.2.6.p5+dfsg-3ubuntu5) vivid; urgency=medium

  * SECURITY UPDATE: symmetric key unauthenticated packet MITM attack
    - debian/patches/CVE-2015-1798.patch: reject packets without MAC in
      ntpd/ntp_proto.c.
    - CVE-2015-1798
  * SECURITY UPDATE: symmetric association DoS attack
    - debian/patches/CVE-2015-1799.patch: don't update state variables when
      authentication fails in ntpd/ntp_proto.c.
    - CVE-2015-1799

Date: Tue, 07 Apr 2015 12:48:31 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu5
-------------- next part --------------
Format: 1.8
Date: Tue, 07 Apr 2015 12:48:31 -0400
Source: ntp
Binary: ntp ntpdate ntp-doc
Architecture: source
Version: 1:4.2.6.p5+dfsg-3ubuntu5
Distribution: vivid
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description:
 ntp        - Network Time Protocol daemon and utility programs
 ntp-doc    - Network Time Protocol documentation
 ntpdate    - client for setting system time from NTP servers
Changes:
 ntp (1:4.2.6.p5+dfsg-3ubuntu5) vivid; urgency=medium
 .
   * SECURITY UPDATE: symmetric key unauthenticated packet MITM attack
     - debian/patches/CVE-2015-1798.patch: reject packets without MAC in
       ntpd/ntp_proto.c.
     - CVE-2015-1798
   * SECURITY UPDATE: symmetric association DoS attack
     - debian/patches/CVE-2015-1799.patch: don't update state variables when
       authentication fails in ntpd/ntp_proto.c.
     - CVE-2015-1799
Checksums-Sha1:
 bcc79ea3db030d3a4a6cde072264fcb5f50ea7ae 2348 ntp_4.2.6.p5+dfsg-3ubuntu5.dsc
 71f74e8140909e2f1a4ba0cedd028389a0b9bac2 87172 ntp_4.2.6.p5+dfsg-3ubuntu5.debian.tar.xz
Checksums-Sha256:
 4ababd3cfb053845e30fc5788a7aa76284b4d3d8cdd61dd5b44c5f0da2a19e64 2348 ntp_4.2.6.p5+dfsg-3ubuntu5.dsc
 5990927e1ec9f54756c8d1475beb4f3709db5db283890004b3902ec0f1c479c6 87172 ntp_4.2.6.p5+dfsg-3ubuntu5.debian.tar.xz
Files:
 3f8798d4af1047714c4f69729c5d7d2f 2348 net optional ntp_4.2.6.p5+dfsg-3ubuntu5.dsc
 cbbc419cd9b2955ef44967c394d20065 87172 net optional ntp_4.2.6.p5+dfsg-3ubuntu5.debian.tar.xz
Original-Maintainer: Debian NTP Team <pkg-ntp-maintainers at lists.alioth.debian.org>


More information about the Vivid-changes mailing list