From 39a6cc6679e381f890144eac4da2c30bfd8baa2a Mon Sep 17 00:00:00 2001 From: Tom Yu Date: Fri, 14 Dec 2007 04:38:28 +0000 Subject: [PATCH] fix CVE-2007-5971: free of non-heap pointer in gss_indicate_mechs() ticket: 5856 tags: pullup target_version: 1.6.4 git-svn-id: svn://anonsvn.mit.edu/krb5/trunk@20178 dc483132-0cff-0310-8789-dd5450dbe970 --- src/lib/gssapi/mechglue/g_initialize.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/lib/gssapi/mechglue/g_initialize.c b/src/lib/gssapi/mechglue/g_initialize.c index e25b1faf0..d47499caf 100644 --- a/src/lib/gssapi/mechglue/g_initialize.c +++ b/src/lib/gssapi/mechglue/g_initialize.c @@ -213,7 +213,7 @@ gss_OID_set *mechSet; free((*mechSet)->elements[j].elements); } free((*mechSet)->elements); - free(mechSet); + free(*mechSet); *mechSet = NULL; return (GSS_S_FAILURE); } -- 2.26.2