1
0
mirror of https://github.com/moparisthebest/curl synced 2024-08-13 17:03:50 -04:00

Curl_input_negotiate: do not delegate GSSAPI credentials

This is a security flaw. See curl advisory 20110623 for details.

Reported by: Richard Silverman
This commit is contained in:
Daniel Stenberg 2011-06-08 00:10:26 +02:00
parent 9016958aa8
commit 5c314c6bb4

View File

@ -243,7 +243,7 @@ int Curl_input_negotiate(struct connectdata *conn, bool proxy,
&neg_ctx->context,
neg_ctx->server_name,
GSS_C_NO_OID,
GSS_C_DELEG_FLAG,
0,
0,
GSS_C_NO_CHANNEL_BINDINGS,
&input_token,