From owner-freebsd-security@FreeBSD.ORG Fri Dec 11 09:19:34 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id B50AB106566C for ; Fri, 11 Dec 2009 09:19:34 +0000 (UTC) (envelope-from pluknet@gmail.com) Received: from mail-bw0-f213.google.com (mail-bw0-f213.google.com [209.85.218.213]) by mx1.freebsd.org (Postfix) with ESMTP id 16B428FC08 for ; Fri, 11 Dec 2009 09:19:33 +0000 (UTC) Received: by bwz5 with SMTP id 5so462290bwz.3 for ; Fri, 11 Dec 2009 01:19:33 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:date:message-id:subject :from:to:content-type; bh=l1bn5YXD8TGJCtq4KdUf6K80Qz1MVRie0jwVxm6kcmY=; b=fxEoOHc6fE45pXfig3/4/NTcefTrnp5W6lat1uryMuHMVtC3900315KQvw7xmY9jqo 9EFr9Wapd/tPddEX5VXtAp/WMpo3Zj1TmrTCjoV2o3YUbx9eMBGPRdUjawDUT95LMN1u mkb2Iq3NIsZLIROKpzJ5VairML2MMOH1ZJXG4= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:content-type; b=Pgb1m8qUYqXGc08VAqP0qqUN20per2uyAj+x8bX3btl9P+Ou4KwcdCbvRwVVErAgtl Bs4pkMHM9zWo8Y9L1X92xVzGAkwiBYD2pHPL3GMSeLUahBI2QicLDn76Nz2B6ZjQquXI LZ2neDD9GLossLLeHaiMrYxTAzjksIhmMRl9M= MIME-Version: 1.0 Received: by 10.204.5.198 with SMTP id 6mr599866bkw.72.1260523173004; Fri, 11 Dec 2009 01:19:33 -0800 (PST) Date: Fri, 11 Dec 2009 12:19:32 +0300 Message-ID: From: pluknet To: freebsd-security@freebsd.org Content-Type: text/plain; charset=ISO-8859-1 Subject: ntpd 4.2.4p8 X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 11 Dec 2009 09:19:34 -0000 Hi. Are there plans on updating contrib/ntp to the latest version? There was at least one security fix (and others at earlier versions): +(4.2.4p8) 2009/12/08 Released by Harlan Stenn + +* [Sec 1331] DoS with mode 7 packets - CVE-2009-3563. + NetBSD already done that on Dec/9 (w/ MFC to 4.0.x). -- wbr, pluknet