Skip to content

Commit

Permalink
MFV r358616:
Browse files Browse the repository at this point in the history
Update ntp-4.2.8p13 --> 4.2.8p14.

The advisory can be found at:
http://support.ntp.org/bin/view/Main/SecurityNotice#\
March_2020_ntp_4_2_8p14_NTP_Rele

No CVEs have been documented yet.

MFC after:	now
Security:	http://support.ntp.org/bin/view/Main/NtpBug3610
		http://support.ntp.org/bin/view/Main/NtpBug3596
		http://support.ntp.org/bin/view/Main/NtpBug3592
  • Loading branch information
cschuber committed Mar 4, 2020
2 parents d718de8 + 5171bc9 commit 2d4e511
Show file tree
Hide file tree
Showing 243 changed files with 12,900 additions and 5,773 deletions.
4 changes: 2 additions & 2 deletions contrib/ntp/COPYRIGHT
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ This file is automatically generated from html/copyright.html

jpg "Clone me," says Dolly sheepishly.

Last update: 2-Jan-2017 11:58 UTC
Last update: 4-Feb-2020 23:47 UTC
__________________________________________________________________

The following copyright notice applies to all files collectively called
Expand Down Expand Up @@ -32,7 +32,7 @@ This file is automatically generated from html/copyright.html
Burnicki is:
***********************************************************************
* *
* Copyright (c) Network Time Foundation 2011-2017 *
* Copyright (c) Network Time Foundation 2011-2020 *
* *
* All Rights Reserved *
* *
Expand Down
96 changes: 96 additions & 0 deletions contrib/ntp/ChangeLog
Original file line number Diff line number Diff line change
@@ -1,3 +1,99 @@
---
(4.2.8p14) 2020/03/03 Released by Harlan Stenn <[email protected]>

* [Sec 3610] process_control() should bail earlier on short packets. stenn@
- Reported by Philippe Antoine
* [Sec 3596] Highly predictable timestamp attack. <[email protected]>
- Reported by Miroslav Lichvar
* [Sec 3592] DoS attack on client ntpd <[email protected]>
- Reported by Miroslav Lichvar
* [Bug 3637] Emit the version of ntpd in saveconfig. stenn@
* [Bug 3636] NMEA: combine time/date from multiple sentences <[email protected]>
* [Bug 3635] Make leapsecond file hash check optional <[email protected]>
* [Bug 3634] Typo in discipline.html, reported by Jason Harrison. stenn@
* [Bug 3628] raw DCF decoding - improve robustness with Zeller's congruence
- implement Zeller's congruence in libparse and libntp <[email protected]>
* [Bug 3627] SIGSEGV on FreeBSD-12 with stack limit and stack gap <[email protected]>
- integrated patch by Cy Schubert
* [Bug 3620] memory leak in ntpq sysinfo <[email protected]>
- applied patch by Gerry Garvey
* [Bug 3619] Honour drefid setting in cooked mode and sysinfo <[email protected]>
- applied patch by Gerry Garvey
* [Bug 3617] Add support for ACE III and Copernicus II receivers <[email protected]>
- integrated patch by Richard Steedman
* [Bug 3615] accelerate refclock startup <[email protected]>
* [Bug 3613] Propagate noselect to mobilized pool servers <[email protected]>
- Reported by Martin Burnicki
* [Bug 3612] Use-of-uninitialized-value in receive function <[email protected]>
- Reported by Philippe Antoine
* [Bug 3611] NMEA time interpreted incorrectly <[email protected]>
- officially document new "trust date" mode bit for NMEA driver
- restore the (previously undocumented) "trust date" feature lost with [bug 3577]
* [Bug 3609] Fixing wrong falseticker in case of non-statistic jitter <[email protected]>
- mostly based on a patch by Michael Haardt, implementing 'fudge minjitter'
* [Bug 3608] libparse fails to compile on S11.4SRU13 and later <[email protected]>
- removed ffs() and fls() prototypes as per Brian Utterback
* [Bug 3604] Wrong param byte order passing into record_raw_stats() in
ntp_io.c <[email protected]>
- fixed byte and paramter order as suggested by [email protected]
* [Bug 3601] Tests fail to link on platforms with ntp_cv_gc_sections_runs=no <[email protected]>
* [Bug 3599] Build fails on linux-m68k due to alignment issues <[email protected]>
- added padding as suggested by John Paul Adrian Glaubitz
* [Bug 3594] ntpd discards messages coming through nmead <[email protected]>
* [Bug 3593] ntpd discards silently nmea messages after the 5th string <[email protected]>
* [Bug 3590] Update refclock_oncore.c to the new GPS date API <[email protected]>
* [Bug 3585] Unity tests mix buffered and unbuffered output <[email protected]>
- stdout+stderr are set to line buffered during test setup now
* [Bug 3583] synchronization error <[email protected]>
- set clock to base date if system time is before that limit
* [Bug 3582] gpsdjson refclock fudgetime1 adjustment is doubled <[email protected]>
* [Bug 3580] Possible bug ntpq-subs (NULL dereference in dogetassoc) <[email protected]>
- Reported by Paulo Neves
* [Bug 3577] Update refclock_zyfer.c to the new GPS date API <[email protected]>
- also updates for refclock_nmea.c and refclock_jupiter.c
* [Bug 3576] New GPS date function API <[email protected]>
* [Bug 3573] nptdate: missleading error message <[email protected]>
* [Bug 3570] NMEA driver docs: talker ID not mentioned, typo <[email protected]>
* [Bug 3569] cleanup MOD_NANO/STA_NANO handling for 'ntpadjtimex()' <[email protected]>
- sidekick: service port resolution in 'ntpdate'
* [Bug 3550] Reproducible build: Respect SOURCE_DATE_EPOCH <[email protected]>
- applied patch by Douglas Royds
* [Bug 3542] ntpdc monlist parameters cannot be set <[email protected]>
* [Bug 3533] ntpdc peer_info ipv6 issues <[email protected]>
- applied patch by Gerry Garvey
* [Bug 3531] make check: test-decodenetnum fails <[email protected]>
- try to harden 'decodenetnum()' against 'getaddrinfo()' errors
- fix wrong cond-compile tests in unit tests
* [Bug 3517] Reducing build noise <[email protected]>
* [Bug 3516] Require tooling from this decade <[email protected]>
- patch by Philipp Prindeville
* [Bug 3515] Refactor ntpdmain() dispatcher loop and group common code <[email protected]>
- patch by Philipp Prindeville
* [Bug 3511] Get rid of AC_LANG_SOURCE() warnings <[email protected]>
- patch by Philipp Prindeville
* [Bug 3510] Flatten out the #ifdef nesting in ntpdmain() <[email protected]>
- partial application of patch by Philipp Prindeville
* [Bug 3491] Signed values of LFP datatypes should always display a sign
- applied patch by Gerry Garvey & fixed unit tests <[email protected]>
* [Bug 3490] Patch to support Trimble Resolution Receivers <[email protected]>
- applied (modified) patch by Richard Steedman
* [Bug 3473] RefID of refclocks should always be text format <[email protected]>
- applied patch by Gerry Garvey (with minor formatting changes)
* [Bug 3132] Building 4.2.8p8 with disabled local libopts fails <[email protected]>
- applied patch by Miroslav Lichvar
* [Bug 3094] ntpd trying to listen for broadcasts on a completely ipv6 network
<[email protected]>
* [Bug 2420] ntpd doesn't run and exits with retval 0 when invalid user
is specified with -u <[email protected]>
- monitor daemon child startup & propagate exit codes
* [Bug 1433] runtime check whether the kernel really supports capabilities
- (modified) patch by Kurt Roeckx <[email protected]>
* Clean up sntp/networking.c:sendpkt() error message. <[email protected]>
* Provide more detail on unrecognized config file parser tokens. <[email protected]>
* Startup log improvements. <[email protected]>
* Update the copyright year.
* html/confopt.html: cleanup. <[email protected]>

---
(4.2.8p13) 2019/03/07 Released by Harlan Stenn <[email protected]>

Expand Down
Loading

0 comments on commit 2d4e511

Please sign in to comment.