[krbdev.mit.edu #6274]

Sam Hartman via RT rt-comment at krbdev.mit.edu
Thu Dec 4 10:53:14 EST 2008


The implementation of krb5_c_decrypt based on the AEAD APIs does not
treat the input argument as constant.  I think you need to copy the
input data before using crypto_type_stream.

--Sam





More information about the krb5-bugs mailing list