svn rev #24707: branches/krb5-1-8/src/kdc/

tlyu@MIT.EDU tlyu at MIT.EDU
Tue Mar 15 19:50:10 EDT 2011


http://src.mit.edu/fisheye/changelog/krb5/?cs=24707
Commit By: tlyu
Log Message:
ticket: 6882
subject: KDC double-free when PKINIT enabled [MITKRB5-SA-2011-003 CVE-2011-0284]
status: resolved
version_fixed: 1.8.4

pull up r24705 from trunk

 ------------------------------------------------------------------------
 r24705 | tlyu | 2011-03-15 17:47:19 -0400 (Tue, 15 Mar 2011) | 8 lines

 ticket: 6881
 subject: KDC double-free when PKINIT enabled [MITKRB5-SA-2011-003 CVE-2011-0284]
 tags: pullup
 target_version: 1.9.1

 Fix a double-free condition in the KDC that can occur during an
 AS-REQ when PKINIT is enabled.


Changed Files:
U   branches/krb5-1-8/src/kdc/do_as_req.c
Modified: branches/krb5-1-8/src/kdc/do_as_req.c
===================================================================
--- branches/krb5-1-8/src/kdc/do_as_req.c	2011-03-15 23:26:53 UTC (rev 24706)
+++ branches/krb5-1-8/src/kdc/do_as_req.c	2011-03-15 23:50:09 UTC (rev 24707)
@@ -784,6 +784,8 @@
                     pad->contents = td[size]->data;
                     pad->length = td[size]->length;
                     pa[size] = pad;
+                    td[size]->data = NULL;
+                    td[size]->length = 0;
                 }
             krb5_free_typed_data(kdc_context, td);
         }




More information about the cvs-krb5 mailing list