bzero() before free()

Damien Miller djm at mindrot.org
Thu Apr 2 08:44:58 EST 2009


On Wed, 1 Apr 2009, miguel.sanders at arcelormittal.com wrote:

> Good point, I also thought of that, but it isn't done all the time
> (sometimes they do, sometimes they don't...)

If you find a place where some sensitive data is not zeroed before
a free() please file a bug.

-d


More information about the openssh-unix-dev mailing list