Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-5023492

SubjectComber removes expired tickets from the wrong set

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: P5 P5
    • 6
    • 5.0
    • security-libs
    • None
    • beta
    • generic
    • generic

      sun.security.jgss.krb5.SubjectComber
      removes expired tickets from a partial copy of the private credential
      set of the subject, instead of the intended internal set of the
      subject. Note that when fixing this problem, jgss should synchronize on
      the set returned by Subject.get*() before iterating through it, and also
      destroy the removed credentials.

            xuelei Xuelei Fan
            duke J. Duke
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: