[krbdev.mit.edu #1546] CVS Commit 
    Tom Yu via RT 
    rt-comment at krbdev.mit.edu
       
    Mon Jun  2 23:18:48 EDT 2003
    
    
  
	* change_password.c (krb_change_password): Explicitly zero the
	session key.  Zero the key derived from the new password.
	* mk_req.c (krb_mk_req): Explicitly zero the session key.
	(krb_mk_req_creds_prealm): Don't zero the session key, in case the
	caller wants to make use of it.
To generate a diff of this commit:
	cvs diff -r1.179 -r1.180 krb5/src/lib/krb4/ChangeLog
	cvs diff -r1.6 -r1.7 krb5/src/lib/krb4/change_password.c
	cvs diff -r1.11 -r1.12 krb5/src/lib/krb4/mk_req.c 
    
    
More information about the krb5-bugs
mailing list