package: moonshot-gss-eap
version: 0.9.2-3
severity: grave

Whenever the last gss-eap security context is deleted, the gss-eap
mechanism shuts down openssl including freeing x_data, error strings,
and engines.
In practice this tends to mean that any other library in the same
process using openssl will fail.
So, for example if you use GSS-API to authenticate a TLS-protected
session, then that session will fail.

This is grave because it breaks unrelated packages.


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to