Return-Path: X-Original-To: rt@krbdev.mit.edu Received: from carter-zimmerman.suchdamage.org (carter-zimmerman.suchdamage.org [69.25.196.178]) by krbdev.mit.edu (Postfix) with ESMTP id 34C09CCF0E for ; Thu, 4 Dec 2008 15:53:14 +0000 (UTC) Received: by carter-zimmerman.suchdamage.org (Postfix, from userid 8042) id 601294268; Thu, 4 Dec 2008 10:52:47 -0500 (EST) To: rt@krbdev.mit.edu CC: lukeh@padl.com Subject: [krbdev.mit.edu #6274] Message-ID: <20081204155247.601294268@carter-zimmerman.suchdamage.org> Date: Thu, 4 Dec 2008 10:52:47 -0500 (EST) From: hartmans@mit.edu (Sam Hartman) RT-Send-Cc: X-RT-Original-Encoding: iso-8859-1 Content-Length: 190 The implementation of krb5_c_decrypt based on the AEAD APIs does not treat the input argument as constant. I think you need to copy the input data before using crypto_type_stream. --Sam