svn rev #18420: trunk/src/ appl/bsd/ appl/gssftp/ftpd/ clients/ksu/	lib/krb4/
    tlyu@MIT.EDU 
    tlyu at MIT.EDU
       
    Tue Aug  8 15:26:41 EDT 2006
    
    
  
Commit By: tlyu
Log Message: 
ticket: new
subject: fix MITKRB5-SA-2006-001: multiple local privilege escalation vulnerabilities
target_version: 1.5.1
tags: pullup
	* src/appl/gssftp/ftpd/ftpd.c (getdatasock, passive):
	* src/appl/bsd/v4rcp.c (main):
	* src/appl/bsd/krcp.c (main):
	* src/appl/bsd/krshd.c (doit):
	* src/appl/bsd/login.c (main): 
	* src/clients/ksu/main.c (sweep_up):
	* src/lib/krb4/kuserok.c (kuserok): Check return values from
	setuid() and related functions to avoid privilege escalation
	vulnerabilities.  Fixes MITKRB5-SA-2006-001. [CVE-2006-3083,
	VU#580124, CVE-2006-3084, VU#401660]
Changed Files:
U   trunk/src/appl/bsd/krcp.c
U   trunk/src/appl/bsd/krshd.c
U   trunk/src/appl/bsd/login.c
U   trunk/src/appl/bsd/v4rcp.c
U   trunk/src/appl/gssftp/ftpd/ftpd.c
U   trunk/src/clients/ksu/main.c
U   trunk/src/lib/krb4/kuserok.c
    
    
More information about the cvs-krb5
mailing list