]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/commit
Heimdal: Fix transit path validation CVE-2017-6594
authorCy Schubert <cy@FreeBSD.org>
Wed, 14 Feb 2024 19:56:18 +0000 (11:56 -0800)
committerCy Schubert <cy@FreeBSD.org>
Thu, 15 Feb 2024 21:27:54 +0000 (13:27 -0800)
commitf8041e3628bd70cf5562a9c13eb3d6af8463e720
tree9a1f253b33c9599e2b4d11bbf1b487c07895a64b
parent57d312b8eac9862ae60da32a9aecb6d9ccf08171
Heimdal: Fix transit path validation CVE-2017-6594

Apply upstream b1e699103. This fixes a bug introduced by upstream
f469fc6 which may in some cases enable bypass of capath policy.

Upstream writes in their commit log:

    Note, this may break sites that rely on the bug.  With the bug some
    incomplete [capaths] worked, that should not have.  These may now break
    authentication in some cross-realm configurations.

Reported by: emaste
Security: CVE-2017-6594
Obtained from: upstream b1e699103
MFC after: 1 week
crypto/heimdal/kdc/krb5tgs.c