[ubuntu/xenial-security] ntp 1:4.2.8p4+dfsg-3ubuntu5.9 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Mon Jul 9 16:42:07 UTC 2018
ntp (1:4.2.8p4+dfsg-3ubuntu5.9) xenial-security; urgency=medium
* SECURITY UPDATE: code execution via buffer overflow in decodearr
- debian/patches/CVE-2018-7183.patch: prevent writing beyons limits in
ntpq/ntpq.c.
- CVE-2018-7183
* SECURITY UPDATE: DoS via certain packets with a zero-origin timestamp
- debian/patches/CVE-2018-7185.patch: add additional checks to
ntpd/ntp_proto.c.
- CVE-2018-7185
ntp (1:4.2.8p4+dfsg-3ubuntu5.8) xenial; urgency=medium
* d/apparmor-profile: fix denial checking for running ntpdate (LP: #1749389)
ntp (1:4.2.8p4+dfsg-3ubuntu5.7) xenial; urgency=medium
* d/ntp.init: fix lock path to match the ntpdate ifup hook. Furthermore
drop the usage of lockfile-progs calls and instead use flock directly.
This is a backport of changes made in 1:4.2.8p7+dfsg-1 (LP: #1706818)
ntp (1:4.2.8p4+dfsg-3ubuntu5.6) xenial; urgency=medium
* debian/ntpdate.if-up: Drop delta to stop/start service around ntpdate
updates - fixes ntp restart storms due to network changes, fixes
accidential start of ntp, avoids issues of ntpdate jumping too far while
running ntp was supposed to drift (LP: #1593907)
Date: 2018-07-06 20:01:12.595681+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/ntp/1:4.2.8p4+dfsg-3ubuntu5.9
-------------- next part --------------
Sorry, changesfile not available.
More information about the Xenial-changes
mailing list