CVE-2022-45141 source4/heimdal: Fix check-des
authorNicolas Williams <nico@cryptonector.com>
Wed, 12 Oct 2011 06:15:13 +0000 (01:15 -0500)
committerStefan Metzmacher <metze@samba.org>
Wed, 7 Dec 2022 18:43:14 +0000 (19:43 +0100)
commit2ea3f2db8087e0a2c4a18c633b039c722cb6f829
treee1d88d0d38913e3a5d39af967ae46f68a42a5062
parent2be27ec1d7f3bfcdcac65bca1db53772535fe7bf
CVE-2022-45141 source4/heimdal: Fix check-des

    The previous fix was incomplete.  But it also finally uncovered an
    old check-des problem that I'd had once and which may have gotten
    papered over by changing the default of one of the *strongest* KDC
    parameters.  The old problem is that we were passing the wrong
    enctype to _kdc_encode_reply(): we were passing the session key
    enctype where the ticket enc-part key's enctype was expected.

    The whole enctype being passed in is superfluous anyways.  Let's
    clean that up next.

(cherry picked from Heimdal commit 4c6976a6bdf8a76c6f3c650ae970d46c931e5c71)

BUG: https://bugzilla.samba.org/show_bug.cgi?id=15214
BUG: https://bugzilla.samba.org/show_bug.cgi?id=15237

Signed-off-by: Joseph Sutton <josephsutton@catalyst.net.nz>
Reviewed-by: Stefan Metzmacher <metze@samba.org>
source4/heimdal/kdc/krb5tgs.c