[krbdev.mit.edu #7093] SVN Commit

Greg Hudson via RT rt-comment at krbdev.mit.edu
Tue Feb 21 14:14:47 EST 2012


In the kadmin protocol, make the access controls for
get_strings/set_string mirror those of get_principal/modify_principal.
Previously, anyone with global list privileges could get or modify
string attributes on any principal.  The impact of this depends on how
generous the kadmind acl is with list permission and whether string
attributes are used in a deployment (nothing in the core code uses
them yet).

CVSSv2 vector: AV:N/AC:M/Au:S/C:P/I:P/A:N/E:H/RL:O/RC:C

http://src.mit.edu/fisheye/changelog/krb5/?cs=25704
Commit By: ghudson
Revision: 25704
Changed Files:
U   trunk/src/kadmin/server/server_stubs.c



More information about the krb5-bugs mailing list