]> git.ipfire.org Git - thirdparty/krb5.git/commitdiff
Null pointer deref in kadmind [CVE-2012-1013]
authorTom Yu <tlyu@mit.edu>
Fri, 15 Jun 2012 18:13:35 +0000 (14:13 -0400)
committerTom Yu <tlyu@mit.edu>
Fri, 15 Jun 2012 18:34:39 +0000 (14:34 -0400)
The fix for #6626 could cause kadmind to dereference a null pointer if
a create-principal request contains no password but does contain the
KRB5_KDB_DISALLOW_ALL_TIX flag (e.g. "addprinc -randkey -allow_tix
name").  Only clients authorized to create principals can trigger the
bug.  Fix the bug by testing for a null password in check_1_6_dummy.

CVSSv2 vector: AV:N/AC:M/Au:S/C:N/I:N/A:P/E:H/RL:O/RC:C

[ghudson@mit.edu: Minor style change and commit message]

(cherry picked from commit c5be6209311d4a8f10fda37d0d3f876c1b33b77b)

ticket: 7178 (new)
version_fixed: 1.8.7
status: resolved

src/lib/kadm5/srv/svr_principal.c

index 469a8e885ab92873e6cd03309355e8439e4edb6e..c9a6881d94c22c08309d173b7a20499280d0f78d 100644 (file)
@@ -196,7 +196,7 @@ check_1_6_dummy(kadm5_principal_ent_t entry, long mask,
     char *password = *passptr;
 
     /* Old-style randkey operations disallowed tickets to start. */
-    if (!(mask & KADM5_ATTRIBUTES) ||
+    if (password == NULL || !(mask & KADM5_ATTRIBUTES) ||
         !(entry->attributes & KRB5_KDB_DISALLOW_ALL_TIX))
         return;