-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 01 Feb 2010 12:24:34 +0000 Source: chrony Binary: chrony Architecture: source amd64 Version: 1.23-6+lenny1 Distribution: stable-security Urgency: high Maintainer: John Hasler <jhasler@debian.org> Changed-By: Nico Golde <nion@debian.org> Description: chrony - Sets your computer's clock from time servers on the Net Changes: chrony (1.23-6+lenny1) stable-security; urgency=high . * Non-maintainer upload by the Security Team. * This update addresses the following security issues: - CVE-2010-0292: chronyd replies to all cmdmon packets from unauthorized hosts with. - CVE-2010-0293: missing memory limit for to keep client information which can lead to memory exhaustion through clients with spoofed IPs - CVE-2010-0294: missing syslog limit could lead to filling up the disc by triggering various log events in a loop. Checksums-Sha1: 4cdac1239c47218bf0664ddf6bb84fe9d00aac43 1014 chrony_1.23-6+lenny1.dsc f0c6b32099329f358dbdb4f62753d2c7cbc13c79 321015 chrony_1.23.orig.tar.gz f5503512981c6b236ed895237a03f45e34c068b0 162829 chrony_1.23-6+lenny1.diff.gz b3b3e8d3917d2b6d7322ff517ea5a47b7ae182c7 334714 chrony_1.23-6+lenny1_amd64.deb Checksums-Sha256: bc74545e07627ce3ace5c4afed4ec9c75f27f8f2ec0a1a5f4e2aa0a3994e0cc3 1014 chrony_1.23-6+lenny1.dsc 889f292458ccb3f20ae4f5872110d776a639f1cda2d1df694eb88a14726832c5 321015 chrony_1.23.orig.tar.gz 000307f56e2b2b2cbd09f848f66ec80a72a0b0e8cd1707b2af2b6c5ebc7ee38d 162829 chrony_1.23-6+lenny1.diff.gz bf0a35f057f8268efdd36da3aefa99ac757da770e68b2affa51a9ce22e2999bd 334714 chrony_1.23-6+lenny1_amd64.deb Files: 20987586fe342a0b48ebe8432f7ab9ef 1014 admin extra chrony_1.23-6+lenny1.dsc ffce77695e55d8efda19ab0b78309c23 321015 admin extra chrony_1.23.orig.tar.gz a6d0c6c4d06b22630b00361f0c0e0e37 162829 admin extra chrony_1.23-6+lenny1.diff.gz 8cdc4b9808d7eb84a901359959bd43d9 334714 admin extra chrony_1.23-6+lenny1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAktmzY8ACgkQHYflSXNkfP+/kwCgrzAM5qCwduum/HzX5qzbs4KL Q2sAn04kUucCmkeSJUqsSlntqP3fpl/M =FmF1 -----END PGP SIGNATURE----- Accepted: chrony_1.23-6+lenny1.diff.gz to main/c/chrony/chrony_1.23-6+lenny1.diff.gz chrony_1.23-6+lenny1.dsc to main/c/chrony/chrony_1.23-6+lenny1.dsc chrony_1.23-6+lenny1_amd64.deb to main/c/chrony/chrony_1.23-6+lenny1_amd64.deb