package/ntp: security bump to version 4.2.8p12
authorArtyom Panfilov <apanfilov@spectracom.com>
Wed, 10 Oct 2018 09:03:05 +0000 (09:03 +0000)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Wed, 10 Oct 2018 19:27:23 +0000 (21:27 +0200)
commitcf9344c45e85ed274cf783271344f4c03138971d
treed60c16a4caa73fcfb11a0cb97451710e9c706888
parent2cf84fe954b4ef1ff8ac78739ffae2f7203d3b8a
package/ntp: security bump to version 4.2.8p12

Release notes:
https://www.nwtime.org/network-time-foundation-publishes-ntp-4-2-8p12

Fixed security issues:

  CVE-2016-1549 / CVE-2018-7170: Sybil vulnerability: ephemeral association
  attack

  CVE-2018-12327: The openhost() function used during command-line hostname
  processing by ntpq and ntpdc can write beyond its buffer limit

Signed-off-by: Artem Panfilov <apanfilov@spectracom.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/ntp/ntp.hash
package/ntp/ntp.mk