[krbdev.mit.edu #7948] git commit
Greg Hudson via RT
rt-comment at krbdev.mit.edu
Wed Jun 25 15:30:52 EDT 2014
Fix unlikely null dereference in mk_cred()
If krb5_encrypt_keyhelper() returns an error, the ciphertext structure
may contain a non-zero length, but it will already have freed the
pointer to its data, making encrypt_credencpart()'s subsequent attempt
to clear and free the memory fail. Remove that logic.
Based on a patch from Jatin Nansi.
https://github.com/krb5/krb5/commit/476284de8dc9a52b5544445cb1b316a417ae88f0
Author: Nalin Dahyabhai <nalin at redhat.com>
Committer: Greg Hudson <ghudson at mit.edu>
Commit: 476284de8dc9a52b5544445cb1b316a417ae88f0
Branch: master
src/lib/krb5/krb/mk_cred.c | 7 -------
1 files changed, 0 insertions(+), 7 deletions(-)
More information about the krb5-bugs
mailing list