summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorBernd Edlinger <bernd.edlinger@hotmail.de>2019-03-17 17:28:24 +0100
committerBernd Edlinger <bernd.edlinger@hotmail.de>2019-03-18 22:47:05 +0100
commit502b871ad4eacc96a31f89d9a9470ca2858da998 (patch)
tree0d8ab5815da5aa30d82523213fce1d193f97c98d
parentc5bc42d7a131cf7a6a2ebd97a7a4a559d01af0f9 (diff)
Clear the point S before freeing in ec_mul_consttime
The secret point R can be recovered from S using the equation R = S - P. The X and Z coordinates should be sufficient for that. Reviewed-by: Paul Dale <paul.dale@oracle.com> (Merged from https://github.com/openssl/openssl/pull/8505)
-rw-r--r--crypto/ec/ec_mult.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/crypto/ec/ec_mult.c b/crypto/ec/ec_mult.c
index 8350082eb4..47c0fc028c 100644
--- a/crypto/ec/ec_mult.c
+++ b/crypto/ec/ec_mult.c
@@ -325,7 +325,7 @@ static int ec_mul_consttime(const EC_GROUP *group, EC_POINT *r,
ret = 1;
err:
- EC_POINT_free(s);
+ EC_POINT_clear_free(s);
BN_CTX_end(ctx);
BN_CTX_free(new_ctx);