MFV r362565:Update 4.2.8p14 --> 4.2.8p15Summary: Systems that use a CMAC algorithm in ntp.keys will not releasea bit of memory on each packet that uses a CMAC keyid, eventually causingntpd to r
MFV r362565:Update 4.2.8p14 --> 4.2.8p15Summary: Systems that use a CMAC algorithm in ntp.keys will not releasea bit of memory on each packet that uses a CMAC keyid, eventually causingntpd to run out of memory and fail. The CMAC cleanup fromhttps://bugs.ntp.org/3447, part of ntp-4.2.8p11, introduced a bug wherebythe CMAC data structure was no longer completely removed.MFC after: 3 daysSecurity: NTP Bug 3661
show more ...
MFV r358616:Update ntp-4.2.8p13 --> 4.2.8p14.The advisory can be found at:http://support.ntp.org/bin/view/Main/SecurityNotice#\March_2020_ntp_4_2_8p14_NTP_ReleNo CVEs have been documented yet
MFV r358616:Update ntp-4.2.8p13 --> 4.2.8p14.The advisory can be found at:http://support.ntp.org/bin/view/Main/SecurityNotice#\March_2020_ntp_4_2_8p14_NTP_ReleNo CVEs have been documented yet.MFC after: nowSecurity: http://support.ntp.org/bin/view/Main/NtpBug3610 http://support.ntp.org/bin/view/Main/NtpBug3596 http://support.ntp.org/bin/view/Main/NtpBug3592
MFV r344878:4.2.8p12 --> 4.2.8p13MFC after: immediatelySecurity: CVE-2019-8936 VuXML: c2576e14-36e2-11e9-9eda-206a8a720317Obtained from: nwtime.org
MFV r338092: ntp 4.2.8p12.Relnotes: yes
MFV r330102: ntp 4.2.8p11
MFV r315791: ntp 4.2.8p10.
MFV r308954:ntp 4.2.8p9.Approved by: so
MFV r301238:ntp 4.2.8p8.Security: CVE-2016-4957, CVE-2016-4953, CVE-2016-4954Security: CVE-2016-4955, CVE-2016-4956Security: FreeBSD-SA-16:24.ntpWith hat: so
MFV r298691:ntp 4.2.8p7.Security: CVE-2016-1547, CVE-2016-1548, CVE-2016-1549, CVE-2016-1550Security: CVE-2016-1551, CVE-2016-2516, CVE-2016-2517, CVE-2016-2518Security: CVE-2016-2519Security:
MFV r298691:ntp 4.2.8p7.Security: CVE-2016-1547, CVE-2016-1548, CVE-2016-1549, CVE-2016-1550Security: CVE-2016-1551, CVE-2016-2516, CVE-2016-2517, CVE-2016-2518Security: CVE-2016-2519Security: FreeBSD-SA-16:16.ntpWith hat: so
MFV r294491: ntp 4.2.8p6.Security: CVE-2015-7973, CVE-2015-7974, CVE-2015-7975Security: CVE-2015-7976, CVE-2015-7977, CVE-2015-7978Security: CVE-2015-7979, CVE-2015-8138, CVE-2015-8139Security:
MFV r294491: ntp 4.2.8p6.Security: CVE-2015-7973, CVE-2015-7974, CVE-2015-7975Security: CVE-2015-7976, CVE-2015-7977, CVE-2015-7978Security: CVE-2015-7979, CVE-2015-8138, CVE-2015-8139Security: CVE-2015-8140, CVE-2015-8158With hat: so
MFV r293415:ntp 4.2.8p5Reviewed by: cy, robertoRelnotes: yesDifferential Revision: https://reviews.freebsd.org/D4828
MFV ntp-4.2.8p4 (r289715)Security: VuXML: c4a18a12-77fc-11e5-a687-206a8a720317Security: CVE-2015-7871Security: CVE-2015-7855Security: CVE-2015-7854Security: CVE-2015-7853Security: CVE-20
MFV ntp-4.2.8p4 (r289715)Security: VuXML: c4a18a12-77fc-11e5-a687-206a8a720317Security: CVE-2015-7871Security: CVE-2015-7855Security: CVE-2015-7854Security: CVE-2015-7853Security: CVE-2015-7852Security: CVE-2015-7851Security: CVE-2015-7850Security: CVE-2015-7849Security: CVE-2015-7848Security: CVE-2015-7701Security: CVE-2015-7703Security: CVE-2015-7704, CVE-2015-7705Security: CVE-2015-7691, CVE-2015-7692, CVE-2015-7702Security: http://support.ntp.org/bin/view/Main/SecurityNotice#October_2015_NTP_Security_VulnerSponsored by: Nginx, Inc.
MFV ntp-4.2.8p3 (r284990).Approved by: roberto, delphijSecurity: VuXML: 0d0f3050-1f69-11e5-9ba9-d050996490d0Security: http://bugs.ntp.org/show_bug.cgi?id=2853Security: https://www.kb.cert.org/vu
MFV ntp-4.2.8p3 (r284990).Approved by: roberto, delphijSecurity: VuXML: 0d0f3050-1f69-11e5-9ba9-d050996490d0Security: http://bugs.ntp.org/show_bug.cgi?id=2853Security: https://www.kb.cert.org/vuls/id/668167Security: http://support.ntp.org/bin/view/Main/SecurityNotice#June_2015_NTP_Security_Vulnerabi
MFV ntp 4.2.8p2 (r281348)Reviewed by: delphij (suggested MFC)Approved by: robertoSecurity: CVE-2015-1798, CVE-2015-1799Security: VuXML ebd84c96-dd7e-11e4-854e-3c970e169bc2MFC aft
MFV ntp 4.2.8p2 (r281348)Reviewed by: delphij (suggested MFC)Approved by: robertoSecurity: CVE-2015-1798, CVE-2015-1799Security: VuXML ebd84c96-dd7e-11e4-854e-3c970e169bc2MFC after: 1 month
MFV ntp 4.2.8p1 (r258945, r275970, r276091, r276092, r276093, r278284)Thanks to roberto for providing pointers to wedge this into HEAD.Approved by: roberto
Clean some 'svn:executable' properties in the tree.Submitted by: Christoph MallonMFC after: 3 days
Merge 4.2.4p8 into contrib (r200452 & r200454).Subversion is being difficult here so take a hammer and get it in.MFC after: 2 weeksSecurity: CVE-2009-3563
Remove build timestamps from the following files:/boot/kernel/hptrr.ko/etc/mail/*.cf/lib/libcrypto.so.5/usr/bin/ntpq/usr/sbin/amd/usr/sbin/iasl/usr/sbin/ntpd/usr/sbin/ntpdate/usr/sbin/ntpdc
Remove build timestamps from the following files:/boot/kernel/hptrr.ko/etc/mail/*.cf/lib/libcrypto.so.5/usr/bin/ntpq/usr/sbin/amd/usr/sbin/iasl/usr/sbin/ntpd/usr/sbin/ntpdate/usr/sbin/ntpdcThere does not appear to be any purpose to having these timestamps, andthey have the irritating consequence that the aforementioned files willbe different every time they are rebuilt.After this commit, the only remaining build timestamps are in the kernel,the boot loaders, /usr/include/osreldate.h (the year in the copyrightnotice), and lib*.a (the timestamps on all of the included .o files).Reviewed by: scottl (hptrr), gshapiro (sendmail), simon (openssl), roberto (ntp), jkim (acpica)Approved by: re (kib)
Merge ntpd & friends 4.2.4p5 from vendor/ntp/dist into head. Next commitwill update usr.sbin/ntp to match this.MFC after: 2 weeks
Virgin import of ntpd 4.2.0
Remove files not present in 4.1.1a import.
Virgin import of ntpd 4.1.1a
Virgin import of ntpd 4.1.0
Virgin import of ntpd 4.0.99b
Virgin import of ntpd 4.0.98f