From 8a74bb5c7becbd7492f4445b852602c3e88ba143 Mon Sep 17 00:00:00 2001 From: Bernd Edlinger Date: Sun, 17 Mar 2019 17:28:24 +0100 Subject: [PATCH] Clear the point S before freeing in ec_scalar_mul_ladder The secret point R can be recovered from S using the equation R = S - P. The X and Z coordinates should be sufficient for that. Reviewed-by: Paul Dale (Merged from https://github.com/openssl/openssl/pull/8504) --- crypto/ec/ec_mult.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/crypto/ec/ec_mult.c b/crypto/ec/ec_mult.c index 9b0aac2313..c76c528048 100644 --- a/crypto/ec/ec_mult.c +++ b/crypto/ec/ec_mult.c @@ -378,7 +378,7 @@ int ec_scalar_mul_ladder(const EC_GROUP *group, EC_POINT *r, err: EC_POINT_free(p); - EC_POINT_free(s); + EC_POINT_clear_free(s); BN_CTX_end(ctx); return ret; -- 2.25.1