svn rev #24111: branches/krb5-1-8/src/lib/krb5/krb/ 
    tlyu@MIT.EDU 
    tlyu at MIT.EDU
       
    Fri May 28 14:41:45 EDT 2010
    
    
  
http://src.mit.edu/fisheye/changelog/krb5/?cs=24111
Commit By: tlyu
Log Message:
ticket: 6734
version_fixed: 1.8.2
status: resolved
pull up r24102 from trunk
 ------------------------------------------------------------------------
 r24102 | ghudson | 2010-05-24 22:44:45 -0400 (Mon, 24 May 2010) | 11 lines
 ticket: 6734
 subject: FAST negotiation could erroneously succeed
 target_version: 1.8.2
 tags: pullup
 When FAST negotiation is performed against an older KDC
 (rep->enc_part2->flags & TKT_FLG_ENC_PA_REP not set),
 krb5int_fast_verify_nego did not set the value of *fast_avail, causing
 stack garbage to be used in init_creds_step_reply.  Initialize
 *fast_avail at the beginning of the function per coding practices.
Changed Files:
U   branches/krb5-1-8/src/lib/krb5/krb/fast.c
Modified: branches/krb5-1-8/src/lib/krb5/krb/fast.c
===================================================================
--- branches/krb5-1-8/src/lib/krb5/krb/fast.c	2010-05-28 18:26:43 UTC (rev 24110)
+++ branches/krb5-1-8/src/lib/krb5/krb/fast.c	2010-05-28 18:41:45 UTC (rev 24111)
@@ -572,6 +572,7 @@
     krb5_data scratch;
     krb5_boolean valid;
 
+    *fast_avail = FALSE;
     if (rep->enc_part2->flags& TKT_FLG_ENC_PA_REP) {
         pa = krb5int_find_pa_data(context, rep->enc_part2->enc_padata,
                                   KRB5_ENCPADATA_REQ_ENC_PA_REP);
    
    
More information about the cvs-krb5
mailing list