#
358660 |
|
05-Mar-2020 |
cy |
This is a direct commit to stable/11:
Stack gap is not supported on stable/11.
|
#
358659 |
|
05-Mar-2020 |
cy |
MFC r358652:
MFV r358616:
Update ntp-4.2.8p13 --> 4.2.8p14.
The advisory can be found at: http://support.ntp.org/bin/view/Main/SecurityNotice#\ March_2020_ntp_4_2_8p14_NTP_Rele
No CVEs have been documented yet.
Security: http://support.ntp.org/bin/view/Main/NtpBug3610 http://support.ntp.org/bin/view/Main/NtpBug3596 http://support.ntp.org/bin/view/Main/NtpBug3592
|
#
352865 |
|
29-Sep-2019 |
cy |
MFC r352304, r352540
r352304: No longer mlock() ntpd pages by default in memory thus allowing its pages to page as necessary.
To restore historic BSD behaviour add the following to ntp.conf: rlimit memlock 32
Discussed on: freebsd-current@ between Sept 6-9, 2019 Reported by: Users using ASLR with stack gap != 0 Reviewed by: ian, kib, rgrimes (all previous versions) Differential Revision: https://reviews.freebsd.org/D21581
r352540: Follow up on r352304 which disabled default mlockall() at startup. Unfortunately though the original tarball supports this in ./configure (for Linux), to fully support disabling of mlockall() by default requires a little extra help otherwise the following is logged in syslog:
Cannot set RLIMIT_MEMLOCK: Operation not permitted
|
#
344884 |
|
07-Mar-2019 |
cy |
MFC r344883:
(MFV r344878:)
4.2.8p12 --> 4.2.8p13
Security: CVE-2019-8936 VuXML: c2576e14-36e2-11e9-9eda-206a8a720317 Obtained from: nwtime.org
|
#
338530 |
|
08-Sep-2018 |
delphij |
MFC r338126: MFV r338092: ntp 4.2.8p12.
Relnotes: yes
|
#
330106 |
|
28-Feb-2018 |
delphij |
MFC r330104: MFV r330102: ntp 4.2.8p11
|
#
316068 |
|
28-Mar-2017 |
delphij |
MFC r315871: MFV r315791: ntp 4.2.8p10.
|
#
302408 |
|
07-Jul-2016 |
gjb |
Copy head@r302406 to stable/11 as part of the 11.0-RELEASE cycle. Prune svn:mergeinfo from the new branch, as nothing has been merged here.
Additional commits post-branch will follow.
Approved by: re (implicit) Sponsored by: The FreeBSD Foundation |
#
298695 |
|
27-Apr-2016 |
delphij |
MFV r298691:
ntp 4.2.8p7.
Security: CVE-2016-1547, CVE-2016-1548, CVE-2016-1549, CVE-2016-1550 Security: CVE-2016-1551, CVE-2016-2516, CVE-2016-2517, CVE-2016-2518 Security: CVE-2016-2519 Security: FreeBSD-SA-16:16.ntp With hat: so
|
#
294554 |
|
22-Jan-2016 |
delphij |
MFV r294491: ntp 4.2.8p6.
Security: CVE-2015-7973, CVE-2015-7974, CVE-2015-7975 Security: CVE-2015-7976, CVE-2015-7977, CVE-2015-7978 Security: CVE-2015-7979, CVE-2015-8138, CVE-2015-8139 Security: CVE-2015-8140, CVE-2015-8158 With hat: so
|
#
293423 |
|
08-Jan-2016 |
delphij |
MFV r293415:
ntp 4.2.8p5
Reviewed by: cy, roberto Relnotes: yes Differential Revision: https://reviews.freebsd.org/D4828
|
#
289764 |
|
22-Oct-2015 |
glebius |
MFV ntp-4.2.8p4 (r289715)
Security: VuXML: c4a18a12-77fc-11e5-a687-206a8a720317 Security: CVE-2015-7871 Security: CVE-2015-7855 Security: CVE-2015-7854 Security: CVE-2015-7853 Security: CVE-2015-7852 Security: CVE-2015-7851 Security: CVE-2015-7850 Security: CVE-2015-7849 Security: CVE-2015-7848 Security: CVE-2015-7701 Security: CVE-2015-7703 Security: CVE-2015-7704, CVE-2015-7705 Security: CVE-2015-7691, CVE-2015-7692, CVE-2015-7702 Security: http://support.ntp.org/bin/view/Main/SecurityNotice#October_2015_NTP_Security_Vulner Sponsored by: Nginx, Inc.
|
#
282408 |
|
04-May-2015 |
cy |
MFV ntp 4.2.8p2 (r281348)
Reviewed by: delphij (suggested MFC) Approved by: roberto Security: CVE-2015-1798, CVE-2015-1799 Security: VuXML ebd84c96-dd7e-11e4-854e-3c970e169bc2 MFC after: 1 month
|
#
280849 |
|
30-Mar-2015 |
cy |
MFV ntp 4.2.8p1 (r258945, r275970, r276091, r276092, r276093, r278284)
Thanks to roberto for providing pointers to wedge this into HEAD.
Approved by: roberto
|
#
200576 |
|
15-Dec-2009 |
roberto |
Merge 4.2.4p8 into contrib (r200452 & r200454).
Subversion is being difficult here so take a hammer and get it in.
MFC after: 2 weeks Security: CVE-2009-3563
|
#
182007 |
|
22-Aug-2008 |
roberto |
Merge ntpd & friends 4.2.4p5 from vendor/ntp/dist into head. Next commit will update usr.sbin/ntp to match this.
MFC after: 2 weeks
|
#
132452 |
|
20-Jul-2004 |
roberto |
This commit was generated by cvs2svn to compensate for changes in r132451, which included commits to RCS files with non-trunk default branches.
|
#
132451 |
|
20-Jul-2004 |
roberto |
Virgin import of ntpd 4.2.0
|
#
106163 |
|
29-Oct-2002 |
roberto |
Virgin import of ntpd 4.1.1a
|
#
82498 |
|
29-Aug-2001 |
roberto |
Virgin import of ntpd 4.1.0
|
#
56746 |
|
28-Jan-2000 |
roberto |
Virgin import of ntpd 4.0.99b
|
#
54359 |
|
09-Dec-1999 |
roberto |
Virgin import of ntpd 4.0.98f
|
#
302408 |
|
07-Jul-2016 |
gjb |
Copy head@r302406 to stable/11 as part of the 11.0-RELEASE cycle. Prune svn:mergeinfo from the new branch, as nothing has been merged here.
Additional commits post-branch will follow.
Approved by: re (implicit) Sponsored by: The FreeBSD Foundation |
#
298695 |
|
27-Apr-2016 |
delphij |
MFV r298691:
ntp 4.2.8p7.
Security: CVE-2016-1547, CVE-2016-1548, CVE-2016-1549, CVE-2016-1550 Security: CVE-2016-1551, CVE-2016-2516, CVE-2016-2517, CVE-2016-2518 Security: CVE-2016-2519 Security: FreeBSD-SA-16:16.ntp With hat: so
|
#
294554 |
|
22-Jan-2016 |
delphij |
MFV r294491: ntp 4.2.8p6.
Security: CVE-2015-7973, CVE-2015-7974, CVE-2015-7975 Security: CVE-2015-7976, CVE-2015-7977, CVE-2015-7978 Security: CVE-2015-7979, CVE-2015-8138, CVE-2015-8139 Security: CVE-2015-8140, CVE-2015-8158 With hat: so
|
#
293423 |
|
08-Jan-2016 |
delphij |
MFV r293415:
ntp 4.2.8p5
Reviewed by: cy, roberto Relnotes: yes Differential Revision: https://reviews.freebsd.org/D4828
|
#
289764 |
|
22-Oct-2015 |
glebius |
MFV ntp-4.2.8p4 (r289715)
Security: VuXML: c4a18a12-77fc-11e5-a687-206a8a720317 Security: CVE-2015-7871 Security: CVE-2015-7855 Security: CVE-2015-7854 Security: CVE-2015-7853 Security: CVE-2015-7852 Security: CVE-2015-7851 Security: CVE-2015-7850 Security: CVE-2015-7849 Security: CVE-2015-7848 Security: CVE-2015-7701 Security: CVE-2015-7703 Security: CVE-2015-7704, CVE-2015-7705 Security: CVE-2015-7691, CVE-2015-7692, CVE-2015-7702 Security: http://support.ntp.org/bin/view/Main/SecurityNotice#October_2015_NTP_Security_Vulner Sponsored by: Nginx, Inc.
|
#
282408 |
|
04-May-2015 |
cy |
MFV ntp 4.2.8p2 (r281348)
Reviewed by: delphij (suggested MFC) Approved by: roberto Security: CVE-2015-1798, CVE-2015-1799 Security: VuXML ebd84c96-dd7e-11e4-854e-3c970e169bc2 MFC after: 1 month
|
#
280849 |
|
30-Mar-2015 |
cy |
MFV ntp 4.2.8p1 (r258945, r275970, r276091, r276092, r276093, r278284)
Thanks to roberto for providing pointers to wedge this into HEAD.
Approved by: roberto
|
#
200576 |
|
15-Dec-2009 |
roberto |
Merge 4.2.4p8 into contrib (r200452 & r200454).
Subversion is being difficult here so take a hammer and get it in.
MFC after: 2 weeks Security: CVE-2009-3563
|
#
182007 |
|
22-Aug-2008 |
roberto |
Merge ntpd & friends 4.2.4p5 from vendor/ntp/dist into head. Next commit will update usr.sbin/ntp to match this.
MFC after: 2 weeks
|
#
132452 |
|
20-Jul-2004 |
roberto |
This commit was generated by cvs2svn to compensate for changes in r132451, which included commits to RCS files with non-trunk default branches.
|
#
132451 |
|
20-Jul-2004 |
roberto |
Virgin import of ntpd 4.2.0
|
#
106163 |
|
29-Oct-2002 |
roberto |
Virgin import of ntpd 4.1.1a
|
#
82498 |
|
29-Aug-2001 |
roberto |
Virgin import of ntpd 4.1.0
|
#
56746 |
|
28-Jan-2000 |
roberto |
Virgin import of ntpd 4.0.99b
|
#
54359 |
|
09-Dec-1999 |
roberto |
Virgin import of ntpd 4.0.98f
|