The tracker stripped the patch from the mail that it sent, but it did
keep it with the original request.

All malloc()/calloc()/free() needs to be done by the same library
version to avoid heap corruption.  This includes the "local" calls
that don't get put into kssl_ctx.

-Kyle H

On 1/30/07, Andrei Pelinescu-Onciul <[EMAIL PROTECTED]> wrote:

The tracker stripped the attached patch, so here's a link to it:
http://www.iptel.org/~andrei/openssl_patches/openssl_kssl_malloc.patch

Andrei

On Jan 30, 2007 at 10:36, Andrei Pelinescu-Onciul via RT <[EMAIL PROTECTED]> 
wrote:
>
>
>
> Versions affected: latest cvs, 0.9.8, 0.9.7  with kerberos support.
>
> kssl functions (kssl.c) use libc malloc/calloc/free instead of openssl
> versions (.e.g. OPENSSL_malloc).
> This can be a problem if some application changes the default mallocs
>  used by openssl (via CRYPTO_set_mem_functions()) and expects openssl
>  to always use the new ones. For example in a multi-process application
>  that uses a common shared memory pool and proprietary mallocs that use
>  this shm pool and in which an openssl connection can "move" from one
>  process to another (e.g. is created in one process, data is read/sent
>  form another one and the ssl ctx is destroyed from yet another one),
>  any "wrong" malloc/free used will lead to a crash.
>
> This bug appears only if openssl is compiled with kerberos support (but
> even if  kerberos is not used).
>
> The attached patch (against cvs) fixes this problem by creating a
>  kssl_calloc function that uses OPENSSL_malloc and by using it (and
>  kssl_free/OPENSSL_free) each time some data that will be saved into
>  kssl_ctx is allocated. Temporary / non-persistent stuff used for the
>  kerberos calls is still allocated with libc malloc/calloc/free.
> The patch applies also to 0.9.8*. Apply with patch -p1 < ...
>
>
> Andrei
> ______________________________________________________________________
> OpenSSL Project                                 http://www.openssl.org
> Development Mailing List                       [email protected]
> Automated List Manager                           [EMAIL PROTECTED]
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [email protected]
Automated List Manager                           [EMAIL PROTECTED]



--

-Kyle H
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [email protected]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to