From tlyu@MIT.EDU Tue Feb 4 16:22:57 1997 Received: from MIT.EDU (SOUTH-STATION-ANNEX.MIT.EDU [18.72.1.2]) by rt-11.MIT.EDU (8.7.5/8.7.3) with SMTP id QAA22310 for ; Tue, 4 Feb 1997 16:22:56 -0500 Received: from TESLA-COIL.MIT.EDU by MIT.EDU with SMTP id AA29639; Tue, 4 Feb 97 16:22:55 EST Received: by tesla-coil.MIT.EDU (5.x/4.7) id AA28514; Tue, 4 Feb 1997 16:22:54 -0500 Message-Id: <9702042122.AA28514@tesla-coil.MIT.EDU> Date: Tue, 4 Feb 1997 16:22:54 -0500 From: tlyu@MIT.EDU Reply-To: tlyu@MIT.EDU To: krb5-bugs@MIT.EDU Subject: rcache is checked wrt uid instead of euid X-Send-Pr-Version: 3.99 >Number: 366 >Category: krb5-libs >Synopsis: rcache is checked wrt ruid instead of euid >Confidential: no >Severity: critical >Priority: medium >Responsible: krb5-unassigned >State: closed >Class: sw-bug >Submitter-Id: unknown >Arrival-Date: Tue Feb 04 16:23:01 EST 1997 >Last-Modified: Tue Mar 25 01:18:18 EST 1997 >Originator: Tom Yu >Organization: mit >Release: 1.0-development >Environment: System: SunOS tesla-coil 5.4 Generic_101945-37 sun4m sparc >Description: In krb5_rc_io_open(), the rcache is checked against the real uid rather than the effective uid. This is a problem when the real uid and the effective uid do not match, as the rcache can only be used once. (discovered by aellwood@mit.edu) >How-To-Repeat: >Fix: >Audit-Trail: State-Changed-From-To: open-closed State-Changed-By: tytso State-Changed-When: Tue Mar 25 01:17:09 1997 State-Changed-Why: Patch applied src/lib/krb5/rcache/ChangeLog 5.38 --> 5.39 src/lib/krb5/rcache/rc_io.c 5.29 --> 5.30 >Unformatted: