[27615] in Kerberos

home help back first fref pref prev next nref lref last post

Re: MITKRB5-SA-2007-002: KDC,

daemon@ATHENA.MIT.EDU (Mike Dopheide)
Tue Apr 3 17:52:34 2007

Message-ID: <4612CC1A.8050400@ncsa.uiuc.edu>
Date: Tue, 03 Apr 2007 16:50:18 -0500
From: Mike Dopheide <dopheide@ncsa.uiuc.edu>
MIME-Version: 1.0
To: Edward Beuerlein <ebeuerlein@aol.com>
In-Reply-To: <4612CADA.8050306@aol.com>
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Specifically,

====================
diff -Nur krb5-040307/lib/kadm5/configure krb5/lib/kadm5/configure
--- krb5-040307/lib/kadm5/configure     2005-11-16 16:47:28.000000000 -0600
+++ krb5/lib/kadm5/configure    2007-04-03 15:15:04.000000000 -0500
@@ -5453,7 +5453,7 @@



-for ac_func in openlog syslog closelog strftime vsprintf
+for ac_func in openlog syslog closelog strftime vsprintf vsnprintf
do
as_ac_var=`echo "ac_cv_func_$ac_func" | $as_tr_sh`
echo "$as_me:$LINENO: checking for $ac_func" >&5
=====================

That's included in the patch I posted and results in -DHAVE_VSNPRINTF=1 
(at least for me it did).

-Mike

Edward Beuerlein wrote:
> Mike,
> What modifications did you make to your src/lib/kadm5/configure script?
>  There is mention in the advisory about making changes to detect
> vsnprintf() but I am not exactly sure how to do that.  I am not a
> developer but need to patch our kerberos code for these 3 security issues.
> -Eddie B.
> ________________________________________________
> Kerberos mailing list           Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
> 
> 
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post