[krbdev.mit.edu #8238] git commit

Greg Hudson via RT rt-comment at krbdev.mit.edu
Mon Aug 31 12:41:19 EDT 2015


Check for null name_type in gss_display_name_ext

It is possible for the input name's name_type to be GSS_C_NO_OID.
g_OID_equal() does not account for GSS_C_NO_OID, so we have to
manually check before use to prevent null pointer dereferences.

https://github.com/krb5/krb5/commit/3fdf09ac9a36581b47f40c9d177e463cc12687ff
Author: Solly Ross <sross at redhat.com>
Committer: Greg Hudson <ghudson at mit.edu>
Commit: 3fdf09ac9a36581b47f40c9d177e463cc12687ff
Branch: master
 src/lib/gssapi/mechglue/g_dsp_name_ext.c |    4 +++-
 1 files changed, 3 insertions(+), 1 deletions(-)



More information about the krb5-bugs mailing list