ntpsec 1.1.0+dfsg1-1ubuntu0.2 source package in Ubuntu

Changelog

ntpsec (1.1.0+dfsg1-1ubuntu0.2) bionic-security; urgency=medium

  * Backport three commits from 1.1.3 to fix (LP: #1812458)
    - CVE-2019-6442: "An authenticated attacker can write one byte out of
      bounds in ntpd via a malformed config request, related to
      config_remotely in ntp_config.c, yyparse in ntp_parser.tab.c, and
      yyerror in ntp_parser.y."
    - CVE-2019-6443: "Because of a bug in ctl_getitem, there is a stack-based
      buffer over-read in read_sysvars in ntp_control.c in ntpd.
    - CVE-2019-6444: "process_control() in ntp_control.c has a stack-based
      buffer over-read because attacker-controlled data is dereferenced by
      ntohl() in ntpd."
    - CVE-2019-6445: "An authenticated attacker can cause a NULL pointer
      dereference and ntpd crash in ntp_control.c, related to ctl_getitem."

 -- Richard Laager <email address hidden>  Fri, 18 Jan 2019 20:07:06 -0600

Upload details

Uploaded by:
Richard Laager
Sponsored by:
Marc Deslauriers
Uploaded to:
Bionic
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
net
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Bionic updates universe misc
Bionic security universe misc

Downloads

File Size SHA-256 Checksum
ntpsec_1.1.0+dfsg1.orig.tar.gz 2.4 MiB 459f3eb870521d124fbcf27dcd1757dd895345cb0ad93eb4c215e39be61d082a
ntpsec_1.1.0+dfsg1-1ubuntu0.2.debian.tar.xz 42.1 KiB f23aaab65dbb93a5ab6f20a56664683f64fe251bee0f3a92a762147dfc4a8224
ntpsec_1.1.0+dfsg1-1ubuntu0.2.dsc 2.5 KiB d1be85f8f950140128aa180ba1be22bfdb76218e532fb7966c461d9881464557

View changes file

Binary packages built by this source

ntpsec: Network Time Protocol daemon and utility programs

 NTP, the Network Time Protocol, is used to keep computer clocks
 accurate by synchronizing them over the Internet or a local network,
 or by following an accurate hardware receiver that interprets GPS,
 DCF-77, or similar time signals.
 .
 This package contains the NTP daemon and utility programs. An NTP
 daemon needs to be running on each host that is to have its clock
 accuracy controlled by NTP. The same NTP daemon is also used to
 provide NTP service to other hosts.
 .
 This is the NTPsec version of NTP. NTPsec is a secure, hardened,
 and improved implementation derived from the original NTP project.
 .
 For more information about the NTP protocol and NTP server
 configuration and operation, install the package "ntpsec-doc".

ntpsec-dbgsym: debug symbols for ntpsec
ntpsec-doc: Network Time Protocol documentation

 NTP, the Network Time Protocol, is used to keep computer clocks
 accurate by synchronizing them over the Internet or a local network,
 or by following an accurate hardware receiver that interprets GPS,
 DCF-77, or similar time signals.
 .
 This package contains HTML documentation for the ntpsec packages (ntpsec,
 ntpsec-ntpdate).
 .
 This is part of NTPsec. NTPsec is a secure, hardened, and improved
 implementation derived from the original NTP project.

ntpsec-ntpdate: client for setting system time from NTP servers

 NTP, the Network Time Protocol, is used to keep computer clocks
 accurate by synchronizing them over the Internet or a local network,
 or by following an accurate hardware receiver that interprets GPS,
 DCF-77, or similar time signals.
 .
 ntpdate is a simple NTP client that sets a system's clock to match
 the time obtained by communicating with one or more NTP servers. It
 is not sufficient, however, for maintaining an accurate clock in the
 long run. ntpdate by itself is useful for occasionally setting the
 time on machines that do not have full-time network access, such as
 laptops.
 .
 This is the NTPsec version of ntpdate. NTPsec is a secure, hardened,
 and improved implementation derived from the original NTP project.
 .
 If the full NTP daemon from the package "ntpsec" is installed, then
 ntpsec-ntpdate is not necessary.

ntpsec-ntpviz: NTP statistics graphing utility

 NTP, the Network Time Protocol, is used to keep computer clocks
 accurate by synchronizing them over the Internet or a local network,
 or by following an accurate hardware receiver that interprets GPS,
 DCF-77, or similar time signals.
 .
 ntpviz analyzes NTP log files and generates statistical plots from
 them. The output is in the form of HTML with images. If Apache is
 installed, it will be served at: /ntpviz
 .
 This is part of NTPsec. NTPsec is a secure, hardened, and improved
 implementation derived from the original NTP project.

python3-ntp: Python 3 NTP Helper Classes

 NTP, the Network Time Protocol, is used to keep computer clocks
 accurate by synchronizing them over the Internet or a local network,
 or by following an accurate hardware receiver that interprets GPS,
 DCF-77, or similar time signals.
 .
 This package contains the Python "ntp" module, which contains helper
 classes for NTP utilities written in Python.
 .
 This is part of NTPsec. NTPsec is a secure, hardened, and improved
 implementation derived from the original NTP project.

python3-ntp-dbgsym: debug symbols for python3-ntp