From owner-cvs-all Thu Apr 5 13:47:24 2001 Delivered-To: cvs-all@freebsd.org Received: from freesbee.wheel.dk (freesbee.wheel.dk [193.162.159.97]) by hub.freebsd.org (Postfix) with ESMTP id EA19737B61B; Thu, 5 Apr 2001 13:47:07 -0700 (PDT) (envelope-from jesper@skriver.dk) Received: by freesbee.wheel.dk (Postfix, from userid 1001) id 3E68E5D5E; Thu, 5 Apr 2001 22:47:07 +0200 (CEST) Date: Thu, 5 Apr 2001 22:47:07 +0200 From: Jesper Skriver To: Poul-Henning Kamp Cc: cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org Subject: Re: cvs commit: src/contrib/ntp/ntpd ntp_control.c Message-ID: <20010405224707.A81542@skriver.dk> References: <200104042307.f34N7Mv79463@freefall.freebsd.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: <200104042307.f34N7Mv79463@freefall.freebsd.org>; from phk@FreeBSD.org on Wed, Apr 04, 2001 at 04:07:22PM -0700 X-PGP-Fingerprint: 6B88 9CE8 66E9 E631 C9C5 5EB4 22AB F0EC F956 1C31 X-PGP-Public-Key: http://freesbee.wheel.dk/~jesper/gpgkey.pub Sender: owner-cvs-all@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.ORG On Wed, Apr 04, 2001 at 04:07:22PM -0700, Poul-Henning Kamp wrote: > phk 2001/04/04 16:07:22 PDT > > Modified files: > contrib/ntp/ntpd ntp_control.c > Log: > Fix a potential ROOT-exploit in NTPD. > > PR: 26358 > Reviewed by: dima > > Revision Changes Path > 1.2 +21 -1 src/contrib/ntp/ntpd/ntp_control.c ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2001-004.txt.asc Say: "Jason Thorpe for changes to not overrun the end of the static buffer" in regard to the patch applied to FreeBSD, are they right, or ? /Jesper -- Jesper Skriver, jesper(at)skriver(dot)dk - CCIE #5456 Work: Network manager @ AS3292 (Tele Danmark DataNetworks) Private: FreeBSD committer @ AS2109 (A much smaller network ;-) One Unix to rule them all, One Resolver to find them, One IP to bring them all and in the zone to bind them. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe cvs-all" in the body of the message