CVE-2010-1320 KDC double free caused by ticket renewal (MITKRB5-SA-2010-004)
authorTom Yu <tlyu@mit.edu>
Wed, 19 May 2010 21:23:09 +0000 (21:23 +0000)
committerTom Yu <tlyu@mit.edu>
Wed, 19 May 2010 21:23:09 +0000 (21:23 +0000)
commite57ea6ff9470d12fd912a1ff00dada11621ed8a1
treeacfc400ca883690030d7ffae03ba3eefe19d034d
parent9c0f73bd27b7778435f32e8c5dbec97ffb00109e
CVE-2010-1320 KDC double free caused by ticket renewal (MITKRB5-SA-2010-004)

pull up r23912 from trunk

 ------------------------------------------------------------------------
 r23912 | tlyu | 2010-04-20 17:12:10 -0400 (Tue, 20 Apr 2010) | 11 lines

 ticket: 6702
 target_version: 1.8.2
 tags: pullup

 Fix CVE-2010-1230 (MITKRB5-SA-2010-004) double-free in KDC triggered
 by ticket renewal.  Add a test case.

 See also http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=577490

 Thanks to Joel Johnson and Brian Almeida for the reports.

ticket: 6727
tags: pullup
target_version: 1.7.2
version_fixed: 1.7.2

git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-7@24065 dc483132-0cff-0310-8789-dd5450dbe970
src/kdc/do_tgs_req.c
src/tests/dejagnu/config/default.exp
src/tests/dejagnu/krb-standalone/standalone.exp