[2943] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

krb5-appl/612: rlogin -a dumps core

daemon@ATHENA.MIT.EDU (ghudson@MIT.EDU)
Sun Jun 14 15:25:09 1998

Resent-From: gnats@rt-11.MIT.EDU (GNATS Management)
Resent-To: krb5-unassigned@RT-11.MIT.EDU
Resent-Reply-To: krb5-bugs@MIT.EDU, ghudson@MIT.EDU
Date: Sun, 14 Jun 1998 15:14:01 -0400
From: ghudson@MIT.EDU
Reply-To: ghudson@MIT.EDU
To: krb5-bugs@MIT.EDU


>Number:         612
>Category:       krb5-appl
>Synopsis:       rlogin -a dumps core
>Confidential:   no
>Severity:       non-critical
>Priority:       low
>Responsible:    krb5-unassigned
>State:          open
>Class:          sw-bug
>Submitter-Id:   unknown
>Arrival-Date:   Sun Jun 14 15:15:01 EDT 1998
>Last-Modified:
>Originator:     Greg Hudson
>Organization:
MIT
>Release:        1.0pl1
>Environment:
	
System: SunOS small-gods.mit.edu 5.6 Generic_105181-04 sun4u sparc SUNW,Ultra-1
Architecture: sun4

>Description:
rlogin -a passes a null value of locuser to kcmd(), which then gets handed to
strlen(), causing a core dump.
>How-To-Repeat:
rlogin -a to a host which accepts krb5 rlogin connections.
>Fix:
Index: krlogin.c
===================================================================
RCS file: /afs/dev.mit.edu/source/repository/third/krb5/src/appl/bsd/krlogin.c,v
retrieving revision 1.2
diff -c -r1.2 krlogin.c
*** krlogin.c	1997/10/19 03:44:28	1.2
--- krlogin.c	1998/06/13 05:12:23
***************
*** 575,581 ****
        authopts |= OPTS_FORWARDABLE_CREDS;
  
      status = kcmd(&sock, &host, debug_port,
! 		  null_local_username ? NULL : pwd->pw_name,
  		  name ? name : pwd->pw_name, term,
  		  0, "host", krb_realm,
  		  &cred,
--- 575,581 ----
        authopts |= OPTS_FORWARDABLE_CREDS;
  
      status = kcmd(&sock, &host, debug_port,
! 		  null_local_username ? "" : pwd->pw_name,
  		  name ? name : pwd->pw_name, term,
  		  0, "host", krb_realm,
  		  &cred,
>Audit-Trail:
>Unformatted:

home help back first fref pref prev next nref lref last post