freebsd-dev/crypto/heimdal/lib/gssapi
Cy Schubert 5abaf08664 heimdal: Fix CVE-2022-4152, signature validation error
When CVE-2022-3437 was fixed by changing memcmp to be a constant
time and the workaround for th e compiler was to add "!=0". However
the logic implmented was inverted resulting in CVE-2022-4152.

Reported by:	Timothy E Zingelman <zingelman _AT_ fnal.gov>
MFC after:	1 day
Security:	CVE-2022-4152
Security:	https://www.cve.org/CVERecord?id=CVE-2022-45142
Security:	https://nvd.nist.gov/vuln/detail/CVE-2022-45142
Security:	https://security-tracker.debian.org/tracker/CVE-2022-45142
Security:	https://bugs.gentoo.org/show_bug.cgi?id=CVE-2022-45142
Security:	https://bugzilla.samba.org/show_bug.cgi?id=15296
Security:	https://www.openwall.com/lists/oss-security/2023/02/08/1
2023-03-09 17:18:49 -08:00
..
gssapi
krb5 heimdal: Fix CVE-2022-4152, signature validation error 2023-03-09 17:18:49 -08:00
mech
ntlm
spnego
ChangeLog
gss_acquire_cred.3
gss-commands.in
gssapi_mech.h
gssapi.3
gssapi.h
gsstool.c
Makefile.am
Makefile.in
test_acquire_cred.c
test_common.c
test_common.h
test_context.c
test_cred.c
test_kcred.c
test_names.c
test_ntlm.c
test_oid.c
version-script.map