Commit Graph

6 Commits

Author SHA1 Message Date
Nicolas Williams
8343733562 kadmind: check ACLs for aliases CVE-2016-2400
CVE-2016-2400

kadmind(8) was not checking for 'add' permission to aliases added via
kadm5_modify_principal().  This is a security vulnerability.  The impact
of this vulnerability is mostly minor because most sites that use
kadmind(8) generally grant roughly the same level of permissions to all
administrators.  However, the impact will be higher for sites that grant
modify privileges to large numbers of less-privileged users.

From what we know of existing deployments of Heimdal, it seems very
likely that the impact of this vulnerability will be minor for most
sites.
2016-02-26 01:04:32 -06:00
Love Hornquist Astrand
72908828b1 remove $Id$ 2009-09-21 10:36:37 -07:00
Love Hörnquist Åstrand
8a69ee2d7c more test acls
git-svn-id: svn://svn.h5l.se/heimdal/trunk/heimdal@23253 ec53bebd-3082-4978-b11e-865c3cabbd6b
2008-06-03 05:28:09 +00:00
Love Hörnquist Åstrand
6e920f8e6c test acls
git-svn-id: svn://svn.h5l.se/heimdal/trunk/heimdal@23252 ec53bebd-3082-4978-b11e-865c3cabbd6b
2008-06-03 05:27:41 +00:00
Love Hörnquist Åstrand
1ca9e6a879 add bar@TEST as admin
git-svn-id: svn://svn.h5l.se/heimdal/trunk/heimdal@22395 ec53bebd-3082-4978-b11e-865c3cabbd6b
2008-01-01 18:24:54 +00:00
Love Hörnquist Åstrand
12fd2a59d3 ACL file for check-admin test.
git-svn-id: svn://svn.h5l.se/heimdal/trunk/heimdal@21464 ec53bebd-3082-4978-b11e-865c3cabbd6b
2007-07-10 16:00:53 +00:00