Hello, in the sources in libads there are malloc calls without a check on the returned value in ads_struct.c at line 44 in krb5_setpw.c at lines 141, 398 in ldap.c at lines 358, 364, 369, 676,740 sasl.c at line 166 free is also used instead of SAFE_FREE Bye Andreas