Re: NTP security hole CVE-2013-5211?

看板FB_security作者時間12年前 (2014/01/13 18:32), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串6/48 (看更多)
On Fri, Jan 10, 2014 at 6:18 AM, Xin Li <delphij@delphij.net> wrote: Hi, We will have an advisory next week. If a NTP server is properly > configured, it's likely that they are not affected > I had this problem in november, and ask to -current to integrate the new versione of ntpd in base (see my mail "[request] ntp upgrade" 11/27/13 http://lists.freebsd.org/pipermail/freebsd-current/2013-November/046822.html ). I tried several workaround with config and policy, and ended up you MUST have 4.2.7 to stop these kind of attacks. I think it's better to upgrade the version in base AND to write a security advisory. Thank you -- Cris, member of G.U.F.I Italian FreeBSD User Group http://www.gufi.org/ _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #1Iqy2YVp (FB_security)
討論串 (同標題文章)
文章代碼(AID): #1Iqy2YVp (FB_security)