From: Tom Yu Date: Fri, 14 Dec 2007 04:38:28 +0000 (+0000) Subject: fix CVE-2007-5971: free of non-heap pointer in gss_indicate_mechs() X-Git-Tag: krb5-1.7-alpha1~767 X-Git-Url: http://git.tremily.us/?a=commitdiff_plain;h=39a6cc6679e381f890144eac4da2c30bfd8baa2a;p=krb5.git fix CVE-2007-5971: free of non-heap pointer in gss_indicate_mechs() ticket: 5856 tags: pullup target_version: 1.6.4 git-svn-id: svn://anonsvn.mit.edu/krb5/trunk@20178 dc483132-0cff-0310-8789-dd5450dbe970 --- diff --git a/src/lib/gssapi/mechglue/g_initialize.c b/src/lib/gssapi/mechglue/g_initialize.c index e25b1faf0..d47499caf 100644 --- a/src/lib/gssapi/mechglue/g_initialize.c +++ b/src/lib/gssapi/mechglue/g_initialize.c @@ -213,7 +213,7 @@ gss_OID_set *mechSet; free((*mechSet)->elements[j].elements); } free((*mechSet)->elements); - free(mechSet); + free(*mechSet); *mechSet = NULL; return (GSS_S_FAILURE); }