[krbdev.mit.edu #3425] Buffer overflows in kdb_load_library could lead to arbitrary code execution

Sam Hartman via RT rt-comment at krbdev.mit.edu
Fri Jan 27 17:34:54 EST 2006



It looks like there is no check to make sure that the database name
and locations both read from the configuration file do not overflow
the statically allocated buffer.

This is probably not a huge deal but it is not something we should ship with.

--Sam




More information about the krb5-bugs mailing list