From owner-freebsd-security@FreeBSD.ORG Tue Jan 14 14:43:28 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 40E81865 for ; Tue, 14 Jan 2014 14:43:28 +0000 (UTC) Received: from keltia.net (cl-90.mrs-01.fr.sixxs.net [IPv6:2a01:240:fe00:59::2]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id F29A31CAC for ; Tue, 14 Jan 2014 14:43:27 +0000 (UTC) Received: from roberto02-aw.eurocontrol.fr (aran.keltia.net [88.191.250.24]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) (Authenticated sender: roberto) by keltia.net (Postfix) with ESMTPSA id 6146552B1; Tue, 14 Jan 2014 15:43:24 +0100 (CET) Date: Tue, 14 Jan 2014 15:43:14 +0100 From: Ollivier Robert To: freebsd-security@freebsd.org, Xin LI Subject: Re: NTP security hole CVE-2013-5211? Message-ID: <20140114144314.GB13757@roberto02-aw.eurocontrol.fr> References: <52CEAD69.6090000@grosbein.net> <81785015-5083-451C-AC0B-4333CE766618@FreeBSD.org> <52CF82C0.9040708@delphij.net> <52D44173.1070007@delphij.net> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: X-Operating-System: MacOS X / Macbook Pro - FreeBSD 7.2 / Dell D820 SMP User-Agent: Mutt/1.5.21 (2010-09-15) X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.17 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 14 Jan 2014 14:43:28 -0000 According to Cristiano Deana on Tue, Jan 14, 2014 at 09:17:51AM +0100: > > I think it's better to upgrade the version in base AND to write a security > > advisory. > > I wish we could, but 4.2.7 is a moving target right now. I think I will stop trying to upgrade to 4.2.6p5 (the one I imported a few weeks ago) and have a look at 4.2.7. -- Ollivier ROBERT -=- FreeBSD: The Power to Serve! -=- roberto@keltia.net In memoriam to Ondine, our 2nd child: http://ondine.keltia.net/