[krbdev.mit.edu #8647] git commit

Greg Hudson via RT rt-comment at KRBDEV-PROD-APP-1.mit.edu
Fri Mar 30 21:07:21 EDT 2018


Zap data when freeing krb5_spake_factor

krb5_spake_factor structures will sometimes hold sensitive data when
second-factor SPAKE is implemented, so should be zapped when freed.

https://github.com/krb5/krb5/commit/9cc94a3f1ce06a4430f684300a747ec079102403
Author: Greg Hudson <ghudson at mit.edu>
Commit: 9cc94a3f1ce06a4430f684300a747ec079102403
Branch: master
 src/lib/krb5/krb/kfree.c |    4 +++-
 1 files changed, 3 insertions(+), 1 deletions(-)



More information about the krb5-bugs mailing list