From 42a8f233f5e8694995e19aead3f0d589fd75aaa8 Mon Sep 17 00:00:00 2001 From: Christian Göttsche Date: Wed, 17 Jan 2024 15:34:05 +0100 Subject: pam_userdb: cleanse crypt data Clease the crypt data to avoid any potential information leakage. --- modules/pam_userdb/pam_userdb.c | 1 + 1 file changed, 1 insertion(+) (limited to 'modules/pam_userdb') diff --git a/modules/pam_userdb/pam_userdb.c b/modules/pam_userdb/pam_userdb.c index 7e1407f4..3bcb4c87 100644 --- a/modules/pam_userdb/pam_userdb.c +++ b/modules/pam_userdb/pam_userdb.c @@ -309,6 +309,7 @@ user_lookup (pam_handle_t *pamh, const char *database, const char *cryptmode, } } #ifdef HAVE_CRYPT_R + pam_overwrite_object(cdata); free(cdata); #endif } -- cgit v1.2.3