[krbdev.mit.edu #8334] git commit
Tom Yu via RT
rt-comment at krbdev.mit.edu
Thu Jan 7 16:28:12 EST 2016
Check context handle in gss_export_sec_context()
After commit 4f35b27a9ee38ca0b557ce8e6d059924a63d4eff, the
context_handle parameter in gss_export_sec_context() is dereferenced
before arguments are validated by val_exp_sec_ctx_args(). With a null
context_handle, the new code segfaults instead of failing gracefully.
Revert this part of the commit and only dereference context_handle if
it is non-null.
(cherry picked from commit b6f29cbd2ab132e336b5435447348400e9a9e241)
https://github.com/krb5/krb5/commit/018f203ff88e8ffe187502a0e97824e697179f3a
Author: Tomas Kuthan <tkuthan at gmail.com>
Committer: Tom Yu <tlyu at mit.edu>
Commit: 018f203ff88e8ffe187502a0e97824e697179f3a
Branch: krb5-1.14
src/lib/gssapi/mechglue/g_exp_sec_context.c | 5 +++--
1 files changed, 3 insertions(+), 2 deletions(-)
More information about the krb5-bugs
mailing list