ntpsec 1.1.1+dfsg1-2ubuntu0.1 source package in Ubuntu

Changelog

ntpsec (1.1.1+dfsg1-2ubuntu0.1) cosmic-security; urgency=medium

  * Backport three commits from 1.1.3 to fix (LP: #1812458)
    - CVE-2019-6442: "An authenticated attacker can write one byte out of
      bounds in ntpd via a malformed config request, related to
      config_remotely in ntp_config.c, yyparse in ntp_parser.tab.c, and
      yyerror in ntp_parser.y."
    - CVE-2019-6443: "Because of a bug in ctl_getitem, there is a stack-based
      buffer over-read in read_sysvars in ntp_control.c in ntpd.
    - CVE-2019-6444: "process_control() in ntp_control.c has a stack-based
      buffer over-read because attacker-controlled data is dereferenced by
      ntohl() in ntpd."
    - CVE-2019-6445: "An authenticated attacker can cause a NULL pointer
      dereference and ntpd crash in ntp_control.c, related to ctl_getitem."

 -- Richard Laager <email address hidden>  Fri, 18 Jan 2019 19:59:19 -0600

Upload details

Uploaded by:
Richard Laager
Sponsored by:
Marc Deslauriers
Uploaded to:
Cosmic
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
net
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
ntpsec_1.1.1+dfsg1.orig.tar.gz 2.4 MiB 6c6480f86bdc7c5c80fe0f64989441a85487e5cd03b27869ee65eeaa6f93ab0d
ntpsec_1.1.1+dfsg1-2ubuntu0.1.debian.tar.xz 44.9 KiB 19540e31421b88996a6d7de72d21296f03ac1afe8f6a1371ab51374df158654d
ntpsec_1.1.1+dfsg1-2ubuntu0.1.dsc 2.4 KiB 23a1a354d3a73273e7c049dbfb2b973afe4c7e0338010d93043c6467ed7d0e8f

View changes file

Binary packages built by this source

ntpsec: No summary available for ntpsec in ubuntu cosmic.

No description available for ntpsec in ubuntu cosmic.

ntpsec-dbgsym: No summary available for ntpsec-dbgsym in ubuntu cosmic.

No description available for ntpsec-dbgsym in ubuntu cosmic.

ntpsec-doc: No summary available for ntpsec-doc in ubuntu cosmic.

No description available for ntpsec-doc in ubuntu cosmic.

ntpsec-ntpdate: No summary available for ntpsec-ntpdate in ubuntu cosmic.

No description available for ntpsec-ntpdate in ubuntu cosmic.

ntpsec-ntpviz: No summary available for ntpsec-ntpviz in ubuntu cosmic.

No description available for ntpsec-ntpviz in ubuntu cosmic.

python3-ntp: No summary available for python3-ntp in ubuntu cosmic.

No description available for python3-ntp in ubuntu cosmic.

python3-ntp-dbgsym: No summary available for python3-ntp-dbgsym in ubuntu cosmic.

No description available for python3-ntp-dbgsym in ubuntu cosmic.