[ntp:security] Cisco ASIG NTP Defect Batch 1

Danny Mayer mayer at pdmconsulting.net
Thu Oct 8 10:11:01 UTC 2015


On 10/8/2015 3:47 AM, Harlan Stenn wrote:
> Folks,
> 
> Seeing a "batch 1" makes me wonder how many other batches there are.
> 
> We also need to decide how soon to release the updates based on batch 1.
> 
> It will be Difficult but possibly doable (not sure yet) to get these
> released as part of 4.2.8p4, in a few days' time.
> 
> If we don't do this soon, I'd like to wait a month before releasing p5,
> and this also depends on if there are more issues coming.

I don't think we should wait on p4 or try and push any new changes into
it. It would mean that proper analysis and testing would be too rushed
to be sure that the fixes were correct and address the problems.

I haven't seen what was sent so I don't know what's in the batch but
it's better to do a p5 if necessary.

Danny



More information about the security mailing list