CVE-2022-3437 source4/heimdal: Check the result of _gsskrb5_get_mech()
authorJoseph Sutton <josephsutton@catalyst.net.nz>
Mon, 15 Aug 2022 04:53:55 +0000 (16:53 +1200)
committerJule Anger <janger@samba.org>
Mon, 24 Oct 2022 05:27:02 +0000 (07:27 +0200)
commitebac8bf0478e19849f83af6d44b73d7ab3afd25b
tree57cdba17d5a94da99b5b12d43b6e6c1a68034c8a
parent5a62eb5734d50fe556934aefa3bac5698372f00e
CVE-2022-3437 source4/heimdal: Check the result of _gsskrb5_get_mech()

We should make sure that the result of 'total_len - mech_len' won't
overflow, and that we don't memcmp() past the end of the buffer.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=15134

Signed-off-by: Joseph Sutton <josephsutton@catalyst.net.nz>
Reviewed-by: Andrew Bartlett <abartlet@samba.org>
selftest/knownfail.d/heimdal-des-overflow
source4/heimdal/lib/gssapi/krb5/decapsulate.c