Fix gssrpc data leakage [CVE-2014-9423]
[MITKRB5-SA-2015-001] In svcauth_gss_accept_sec_context(), do not copy
bytes from the union context into the handle field we send to the
client. We do not use this handle field, so just supply a fixed
string of "xxxx".
In gss_union_ctx_id_struct, remove the unused "interposer" field which
was causing part of the union context to remain uninitialized.
(cherry picked from commit
5bb8a6b9c9eb8dd22bc9526751610aaa255ead9c)
ticket: 8070 (new)
version_fixed: 1.12.3
status: resolved