pull up r23832 from trunk
authorTom Yu <tlyu@mit.edu>
Tue, 23 Mar 2010 19:08:53 +0000 (19:08 +0000)
committerTom Yu <tlyu@mit.edu>
Tue, 23 Mar 2010 19:08:53 +0000 (19:08 +0000)
commit8096a4aa162f87aaf2129a7300a3645518074b13
tree5d1b2edebbfaa68e9aedbc87051965212c59bf24
parent186b7a67c1d14aa270139f6264759c8cbc97b18a
pull up r23832 from trunk

 ------------------------------------------------------------------------
 r23832 | tlyu | 2010-03-23 11:53:52 -0700 (Tue, 23 Mar 2010) | 8 lines

 ticket: 6690
 target_version: 1.8.1
 tags: pullup
 subject: MITKRB5-SA-2010-002 CVE-2010-0628 denial of service in SPNEGO

 The SPNEGO implementation in krb5-1.7 and later could crash due to
 assertion failure when receiving some sorts of invalid GSS-API tokens.

ticket: 6690
version_fixed: 1.8.1
status: resolved

git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-8@23833 dc483132-0cff-0310-8789-dd5450dbe970
src/lib/gssapi/spnego/spnego_mech.c