diff options
author | Tom Yu <tlyu@mit.edu> | 2005-07-12 19:56:56 +0000 |
---|---|---|
committer | Tom Yu <tlyu@mit.edu> | 2005-07-12 19:56:56 +0000 |
commit | 9755aac29ccaac6977a93aa4305963ac29748641 (patch) | |
tree | aefd75bbc89cee3f463e37ba5a154b14a8712bc7 /src/lib/krb5/krb/unparse.c | |
parent | 9ab48cb7d2150c1b0e427bbfcb4a310b29121431 (diff) | |
download | krb5-9755aac29ccaac6977a93aa4305963ac29748641.tar.gz krb5-9755aac29ccaac6977a93aa4305963ac29748641.tar.xz krb5-9755aac29ccaac6977a93aa4305963ac29748641.zip |
fix MITKRB5-SA-2005-002 KDC double-free and heap overflow
Fix for MITKRB5-SA-2005-002
* KDC double-free [CAN-2005-1174, VU#259798]
* krb5_unparse_name heap overflow [CAN-2005-1175, VU#885830]
Thanks to Daniel Wachdorf.
ticket: new
flags: pullup
target_version: 1.4.2
git-svn-id: svn://anonsvn.mit.edu/krb5/trunk@17298 dc483132-0cff-0310-8789-dd5450dbe970
Diffstat (limited to 'src/lib/krb5/krb/unparse.c')
-rw-r--r-- | src/lib/krb5/krb/unparse.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/src/lib/krb5/krb/unparse.c b/src/lib/krb5/krb/unparse.c index badb5bf97..a67636641 100644 --- a/src/lib/krb5/krb/unparse.c +++ b/src/lib/krb5/krb/unparse.c @@ -91,6 +91,8 @@ krb5_unparse_name_ext(krb5_context context, krb5_const_principal principal, regi totalsize++; totalsize++; /* This is for the separator */ } + if (nelem == 0) + totalsize++; /* * Allocate space for the ascii string; if space has been |