[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#782173: RFS: chrony/1.30-2 [RC] -- Set the computer clock from time servers on the Net



Control: owner -1 !
Control: tag -1 + moreinfo

On Thu, 09 Apr 2015 01:00:12 +0200, Joachim Wiedorn wrote:

> I am looking for a sponsor for my package "chrony"
[..]
>   dget -x http://mentors.debian.net/debian/pool/main/c/chrony/chrony_1.30-2.dsc

I'd be willing to sponsor this upload, I just saw one minor glitch:
 
> Changes since the last upload:
> 
>   * New upstream release.
>   * It includes the following security fixes (Closes: #782160):
>     - Fix CVE-2015-1853: Protect authenticated symmetric NTP
>                          associations against DoS attacks.
>     - Fix CVE-2015-1821: Fix access configuration with subnet
>                          size indivisible by 4.
>     - Fix CVE-2015-1822: Fix initialization of reply slots for
>                          authenticated commands.
>   * debian/control:
>    - Update e-mail address of myself.
>    - Add Vincent Blut as co-maintainer.

It seems that d/changlog is not really correct, in a slightly
confusing way: This is no new upstream release but a backport of some
fixes from the new upstream release to the current version. At least
I guess so :)

(And for and upload to unstable targetting jessie I'd probably also
drop the changes in d/control to make the diff smaller for the
release team; although it propbably doesn't matter for those
technically trivial changes.)


Cheers,
gregor

-- 
 .''`.  Homepage: http://info.comodo.priv.at/ - OpenPGP key 0xBB3A68018649AA06
 : :' : Debian GNU/Linux user, admin, and developer -  https://www.debian.org/
 `. `'  Member of VIBE!AT & SPI, fellow of the Free Software Foundation Europe
   `-   NP: Ostbahn-Kurti & Die Chefpartie: Tequila Sunrise

Attachment: signature.asc
Description: Digital Signature


Reply to: