[krbdev.mit.edu #2988] CVS Commit
Tom Yu via RT
rt-comment at krbdev.mit.edu
Tue Mar 29 16:21:21 EST 2005
* telnet.c (slc_add_reply, slc_end_reply): Fix buffer overflow
vulnerability by checking lengths.
(env_opt_add): Ensure buffer allocation is sufficiently large,
accounting for expansion during IAC quoting.
To generate a diff of this commit:
cvs diff -r5.90 -r5.91 krb5/src/appl/telnet/telnet/ChangeLog
cvs diff -r5.18 -r5.19 krb5/src/appl/telnet/telnet/telnet.c
More information about the krb5-bugs
mailing list