[krbdev.mit.edu #7838] git commit

Greg Hudson via RT rt-comment at krbdev.mit.edu
Wed Jan 22 19:24:57 EST 2014


Fix gss_pseudo_random leak on zero length output

Nobody is likely to ever ask for zero bytes of output from
gss_pseudo_random, but if they do, just return an empty buffer without
allocating.  Otherwise we leak memory because gss_release_buffer
doesn't do anything to buffers with length 0.

https://github.com/krb5/krb5/commit/a44945dfa6502d4cd99943b2448ada389bc22b73
Author: Greg Hudson <ghudson at mit.edu>
Commit: a44945dfa6502d4cd99943b2448ada389bc22b73
Branch: master
 src/lib/gssapi/krb5/prf.c |    3 +++
 1 files changed, 3 insertions(+), 0 deletions(-)



More information about the krb5-bugs mailing list