pull up r19171 from trunk
authorTom Yu <tlyu@mit.edu>
Tue, 27 Feb 2007 22:41:24 +0000 (22:41 +0000)
committerTom Yu <tlyu@mit.edu>
Tue, 27 Feb 2007 22:41:24 +0000 (22:41 +0000)
 r19171@cathode-dark-space:  raeburn | 2007-02-23 19:56:23 -0500
 ticket: 5445
 status: open

 If a reflection is detected, zap the message buffer pointer output
 argument as well as actually freeing the buffer.  (Found while using
 the gsstest option to exercise error conditions.)

ticket: 5445

git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-6@19186 dc483132-0cff-0310-8789-dd5450dbe970

src/lib/gssapi/krb5/k5unseal.c

index 30845bd85a88f08de0623f28c54344f7d0387f82..8c999868efccf37bad2280bfed3f99e147fadd25 100644 (file)
@@ -457,8 +457,11 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer,
 
     if ((ctx->initiate && direction != 0xff) ||
        (!ctx->initiate && direction != 0)) {
-       if (toktype == KG_TOK_SEAL_MSG)
+       if (toktype == KG_TOK_SEAL_MSG) {
            xfree(token.value);
+           message_buffer->value = NULL;
+           message_buffer->length = 0;
+       }
        *minor_status = G_BAD_DIRECTION;
        return(GSS_S_BAD_SIG);
     }