freebsd-nq/crypto/heimdal/lib
Xin LI 49426905b3 MFV r320905: Import upstream fix for CVE-2017-11103.
In _krb5_extract_ticket() the KDC-REP service name must be obtained from
encrypted version stored in 'enc_part' instead of the unencrypted version
stored in 'ticket'.  Use of the unecrypted version provides an
opportunity for successful server impersonation and other attacks.

Submitted by:	hrs
Obtained from:	Heimdal
Security:	FreeBSD-SA-17:05.heimdal
Security:	CVE-2017-11103
2017-07-12 07:19:06 +00:00
..
asn1
com_err
gssapi
hdb
heimdal
hx509 Remove duplicate symbol from libhx509 version-script.map 2016-08-22 18:50:57 +00:00
ipc
kadm5
kafs
krb5 MFV r320905: Import upstream fix for CVE-2017-11103. 2017-07-12 07:19:06 +00:00
ntlm
roken Renumber copyright clause 4 2017-02-28 23:42:47 +00:00
sl
sqlite
vers
wind
Makefile.am
Makefile.in