The check which introduced the bug for cve-2012-1016 was brought in when pkinit agility was introduced, upstream's commit 3725d22140c23a376dd79b69d130be8e2b91005f on 19 Sept 2011. The first release to include this code was krb5-1.10; the 1.8 version in squeeze is too old for this bug.

-Ben Kaduk


--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to