Clear the point S before freeing in ec_mul_consttime
authorBernd Edlinger <bernd.edlinger@hotmail.de>
Sun, 17 Mar 2019 16:28:24 +0000 (17:28 +0100)
committerBernd Edlinger <bernd.edlinger@hotmail.de>
Mon, 18 Mar 2019 21:47:05 +0000 (22:47 +0100)
commit502b871ad4eacc96a31f89d9a9470ca2858da998
tree0d8ab5815da5aa30d82523213fce1d193f97c98d
parentc5bc42d7a131cf7a6a2ebd97a7a4a559d01af0f9
Clear the point S before freeing in ec_mul_consttime

The secret point R can be recovered from S using the equation R = S - P.
The X and Z coordinates should be sufficient for that.

Reviewed-by: Paul Dale <paul.dale@oracle.com>
(Merged from https://github.com/openssl/openssl/pull/8505)
crypto/ec/ec_mult.c