From: | tlyu@mit.edu |
Subject: | SVN Commit |
pull up r23912 from trunk
------------------------------------------------------------------------
r23912 | tlyu | 2010-04-20 17:12:10 -0400 (Tue, 20 Apr 2010) | 11 lines
ticket: 6702
target_version: 1.8.2
tags: pullup
Fix CVE-2010-1230 (MITKRB5-SA-2010-004) double-free in KDC triggered
by ticket renewal. Add a test case.
See also http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=577490
Thanks to Joel Johnson and Brian Almeida for the reports.
https://github.com/krb5/krb5/commit/e57ea6ff9470d12fd912a1ff00dada11621ed8a1
Commit By: tlyu
Revision: 24065
Changed Files:
U branches/krb5-1-7/src/kdc/do_tgs_req.c
U branches/krb5-1-7/src/tests/dejagnu/config/default.exp
U branches/krb5-1-7/src/tests/dejagnu/krb-standalone/standalone.exp