[krbdev.mit.edu #8926] git commit

"Greg Hudson via RT" <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.bugs
Message-ID <[email protected]>
<URL: https://krbdev.mit.edu/rt/Ticket/Display.html?id=8926 >


Allow gss_unwrap_iov() of unpadded RC4 tokens

Windows Remote Management, when used with an RC4 session key, appears
to generate GSS wrap tokens with no padding instead of the expected
one byte (RFC 4757 section 7.3).  These tokens cannot be decoded with
gss_unwrap() or a STREAM buffer (even with Microsoft SSPI), but SSPI
allows them to be decoded using explicit IOVs with either a
zero-length padding buffer or no padding buffer.  Allow these cases to
work in kg_fixup_padding_iov().  (It is already possible to make this
work with HEADER | DATA | DATA, but only by
accident--kg_fixup_padding_iov() doesn't find a data buffer because
kg_locate_iov() only looks for singleton buffers, so it exits early.)

(cherry picked from commit 3f204ddd567715ef360b4bb0b32961b6a9877f9d)

https://github.com/krb5/krb5/commit/4c51048aee3ac1b6f61734e10aae123346f2549d
Author: Greg Hudson <[email protected]>
Commit: 4c51048aee3ac1b6f61734e10aae123346f2549d
Branch: krb5-1.18
 src/lib/gssapi/krb5/util_crypt.c |    9 +++------
 1 files changed, 3 insertions(+), 6 deletions(-)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.