svn rev #24950: branches/krb5-1-9/src/kdc/

tlyu@MIT.EDU tlyu at MIT.EDU
Thu Jun 9 17:08:38 EDT 2011


http://src.mit.edu/fisheye/changelog/krb5/?cs=24950
Commit By: tlyu
Log Message:
ticket: 6885
version_fixed: 1.9.2
status: resolved

pull up r24724 from trunk

 ------------------------------------------------------------------------
 r24724 | ghudson | 2011-03-17 18:10:44 -0400 (Thu, 17 Mar 2011) | 9 lines

 ticket: 6885
 subject: KDC memory leak of reply padata for FAST replies
 target_version: 1.9.1
 tags: pullup

 kdc_fast_response_handle_padata() replaces rep->padata, causing the
 old value to be leaked.  As a minimal fix, free the old value of
 rep->padata before replacing it.


Changed Files:
U   branches/krb5-1-9/src/kdc/fast_util.c
Modified: branches/krb5-1-9/src/kdc/fast_util.c
===================================================================
--- branches/krb5-1-9/src/kdc/fast_util.c	2011-06-09 21:08:34 UTC (rev 24949)
+++ branches/krb5-1-9/src/kdc/fast_util.c	2011-06-09 21:08:38 UTC (rev 24950)
@@ -339,6 +339,7 @@
         pa[0].length = encrypted_reply->length;
         pa[0].contents = (unsigned char *)  encrypted_reply->data;
         pa_array[0] = &pa[0];
+        krb5_free_pa_data(kdc_context, rep->padata);
         rep->padata = pa_array;
         pa_array = NULL;
         free(encrypted_reply);




More information about the cvs-krb5 mailing list