[krbdev.mit.edu #9085] git commit
"Greg Hudson via RT" <[email protected]> Tue, 11 Jul 2023 18:56:42 -0400
| Newsgroups | gmane.comp.encryption.kerberos.bugs |
|---|---|
| Message-ID | <[email protected]> |
<URL: https://krbdev.mit.edu/rt/Ticket/Display.html?id=9085 > Fix read overruns in SPNEGO parsing Fix three read overruns discovered by the GitHub Security Lab team (GHSL-2023-016, GHSL-2023-017, and GHSL-2023-018) using OSS-Fuzz. In get_mech_set(), error out if gss_add_oid_set_member() fails rather than continue the loop and increment i past the current bound of returned_mechSet. In g_verify_neg_token_init(), check for zero-byte sequences before reading tag bytes, and reduce cur_size by one to account for the tag byte when calling gssint_get_der_length(). (cherry picked from commit 47c2a12830dbd7fb8e13c239ddc0ac74129a91f6) https://github.com/krb5/krb5/commit/eb886f626526769e596443314bcbe4e8bd9d84ee Author: Greg Hudson <[email protected]> Commit: eb886f626526769e596443314bcbe4e8bd9d84ee Branch: krb5-1.20 src/lib/gssapi/spnego/spnego_mech.c | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-)