Bug#825856: closed by Dererk <der...@debian.org> (Re: Bug#825856: openntpd: CVE-2016-5117)

2016-11-11 Thread Salvatore Bonaccorso
Hi, On Fri, Nov 11, 2016 at 04:45:04PM +, Debian Bug Tracking System wrote: > I've checked this back in May when the report was originally filled but > I was unable to reply back at that time confirming we were not affected > but the issue. > This option is not enabled at build time, which

Bug#825856: openntpd: CVE-2016-5117

2016-05-30 Thread Salvatore Bonaccorso
Source: openntpd Version: 1:5.7p4-4 Severity: normal Tags: security upstream patch Hi, the following vulnerability was published for openntpd. CVE-2016-5117[0]: OpenNTPD not verifying CN during HTTPS constraints request As far I can tell we though are not affected in default Debian