New Debian ntp 1:4.2.8p12+dfsg-4+deb10u1 fixes: This update addresses the following issues: 1:4.2.8p12+dfsg-4+deb10u1 (Wed, 11 Dec 2024 10:33:29 +0800) * Non-maintainer upload by the ELTS Team. * Backport upstream fixes: - CVE-2020-11868: DoS attack on unauthenticated client - CVE-2020-15025: DoS due to memory leak when CMAC keys in use - CVE-2023-26555: DoS in driver for Trimble Palisade GPS timing receiver.
--- mirror/ftp/pool/main/n/ntp/ntp_4.2.8p12+dfsg-4.dsc +++ apt/ucs_5.0-0-errata5.0-9/source/ntp_4.2.8p12+dfsg-4+deb10u1.dsc @@ -1,3 +1,11 @@ +1:4.2.8p12+dfsg-4+deb10u1 [Wed, 11 Dec 2024 10:33:29 +0800] Sean Whitton <spwhitton@spwhitton.name>: + + * Non-maintainer upload by the ELTS Team. + * Backport upstream fixes: + - CVE-2020-11868: DoS attack on unauthenticated client + - CVE-2020-15025: DoS due to memory leak when CMAC keys in use + - CVE-2023-26555: DoS in driver for Trimble Palisade GPS timing receiver. + 1:4.2.8p12+dfsg-4 [Thu, 21 Mar 2019 23:42:36 +0100] Bernhard Schmidt <berni@debian.org>: * CVE-2019-8936: Crafted null dereference attack in authenticated <http://piuparts.knut.univention.de/5.0-9/#4417198311284719498>
OK: bug OK: yaml OK: announce_errata OK: patch ~OK: piuparts Freexian provide new *-dbgsym [5.0-9] e43c374d5a Bug #57807: ntp 1:4.2.8p12+dfsg-4+deb10u1 doc/errata/staging/ntp.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) [5.0-9] c8242d6d3b Bug #57807: ntp 1:4.2.8p12+dfsg-4+deb10u1 doc/errata/staging/ntp.yaml | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x1192>