[22335] in Kerberos

home help back first fref pref prev next nref lref last post

Re: MITKRB5-SA-2004-002: double-free vulnerabilities

daemon@ATHENA.MIT.EDU (Mike Friedman)
Tue Aug 31 17:02:04 2004

Date: Tue, 31 Aug 2004 13:58:22 -0700 (PDT)
From: Mike Friedman <mikef@ack.berkeley.edu>
To: kerberos@mit.edu
In-Reply-To: <ldvhdqjb1p6.fsf@cathode-dark-space.mit.edu>
Message-ID: <Pine.GSO.4.58.0408311351571.29577@ack.Berkeley.EDU>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
cc: kerberos-announce@mit.edu
Errors-To: kerberos-bounces@mit.edu

On Tue, 31 Aug 2004 at 14:29 (-0400), Tom Yu wrote:

>     + If you are running krb5-1.2 through krb5-1.2.7, and have not
>       applied the patches to disable krb4 cross-realm functionality,
>       apply 2004-002-patch_1.2.7.txt.

I just downloaded the above patch and the corresponding detached PGP
signature.  But the signature doesn't verify!  (I tried more than once).

I have no problem getting the 2004-003 patch to verify against its
detached signature.

Is there a problem with the 2004-002 patch?

In both cases, I used 'lynx -source' to download directly from the
specified URLs.

Thanks.

Mike

------------------------------------------------------------------------------
Mike Friedman                             System and Network Security
mikef@ack.Berkeley.EDU                    2484 Shattuck Avenue
1-510-642-1410                            University of California at Berkeley
http://ack.Berkeley.EDU/~mikef            http://security.berkeley.edu
------------------------------------------------------------------------------
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post