Deleted Added
full compact
NEWS (358659) NEWS (362716)
1---
1---
2NTP 4.2.8p15 (Harlan Stenn <stenn@ntp.org>, 2020 Jun 23)
3
4Focus: Security, Bug fixes
5
6Severity: MEDIUM
7
8This release fixes one vulnerability: Associations that use CMAC
9authentication between ntpd from versions 4.2.8p11/4.3.97 and
104.2.8p14/4.3.100 will leak a small amount of memory for each packet.
11Eventually, ntpd will run out of memory and abort.
12
13It also fixes 13 other bugs.
14
15* [Sec 3661] memory leak with AES128CMAC keys <perlinger@ntp.org>
16* [Bug 3670] Regression from bad merger between 3592 and 3596 <perlinger@>
17 - Thanks to Sylar Tao
18* [Bug 3667] decodenetnum fails with numeric port <perlinger@ntp.org>
19 - rewrite 'decodenetnum()' in terms of inet_pton
20* [Bug 3666] avoid unlimited receive buffer allocation <perlinger@ntp.org>
21 - limit number of receive buffers, with an iron reserve for refclocks
22* [Bug 3664] Enable openSSL CMAC support on Windows <burnicki@ntp.org>
23* [Bug 3662] Fix build errors on Windows with VS2008 <burnicki@ntp.org>
24* [Bug 3660] Manycast orphan mode startup discovery problem. <stenn@ntp.org>
25 - integrated patch from Charles Claggett
26* [Bug 3659] Move definition of psl[] from ntp_config.h to
27 ntp_config.h <perlinger@ntp.org>
28* [Bug 3657] Wrong "Autokey group mismatch" debug message <perlinger@ntp.org>
29* [Bug 3655] ntpdc memstats hash counts <perlinger@ntp.org>
30 - fix by Gerry garvey
31* [Bug 3653] Refclock jitter RMS calculation <perlinger@ntp.org>
32 - thanks to Gerry Garvey
33* [Bug 3646] Avoid sync with unsync orphan <perlinger@ntp.org>
34 - patch by Gerry Garvey
35* [Bug 3644] Unsynchronized server [...] selected as candidate <perlinger@ntp.org>
36* [Bug 3639] refclock_jjy: TS-JJY0x can skip time sync depending on the STUS reply. <abe@ntp.org>
37 - applied patch by Takao Abe
38
39---
2NTP 4.2.8p14 (Harlan Stenn <stenn@ntp.org>, 2020 Mar 03)
3
4Focus: Security, Bug fixes, enhancements.
5
6Severity: MEDIUM
7
8This release fixes three vulnerabilities: a bug that causes causes an ntpd
9instance that is explicitly configured to override the default and allow

--- 3571 unchanged lines hidden ---
40NTP 4.2.8p14 (Harlan Stenn <stenn@ntp.org>, 2020 Mar 03)
41
42Focus: Security, Bug fixes, enhancements.
43
44Severity: MEDIUM
45
46This release fixes three vulnerabilities: a bug that causes causes an ntpd
47instance that is explicitly configured to override the default and allow

--- 3571 unchanged lines hidden ---