CVE-2010-1321 GSS-API lib null pointer deref (MITKRB5-SA-2010-005)
authorTom Yu <tlyu@mit.edu>
Wed, 19 May 2010 21:23:18 +0000 (21:23 +0000)
committerTom Yu <tlyu@mit.edu>
Wed, 19 May 2010 21:23:18 +0000 (21:23 +0000)
commit03d3e67fc1fb2d3542075bfaa343fce46bbdb852
tree4397721601652c59024313c2e0dd8bf50ebadfd3
parentbaaf8dd1189ab9f1c6d2d111ff42d7fb4f313435
CVE-2010-1321 GSS-API lib null pointer deref (MITKRB5-SA-2010-005)

pull up r24056 from trunk

 ------------------------------------------------------------------------
 r24056 | tlyu | 2010-05-19 14:09:37 -0400 (Wed, 19 May 2010) | 8 lines

 ticket: 6725
 subject: CVE-2010-1321 GSS-API lib null pointer deref (MITKRB5-SA-2010-005)
 tags: pullup
 target_version: 1.8.2

 Make krb5_gss_accept_sec_context() check for a null authenticator
 checksum pointer before attempting to dereference it.

ticket: 6729
target_version: 1.7.2
version_fixed: 1.7.2
status: resolved

git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-7@24067 dc483132-0cff-0310-8789-dd5450dbe970
src/lib/gssapi/krb5/accept_sec_context.c