Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 17 Oct 1996 20:41:14 +0200
From:      Poul-Henning Kamp <phk@critter.tfs.com>
To:        Guido van Rooij <guido@freebsd.org>
Cc:        CVS-committers@freebsd.org, cvs-all@freebsd.org, cvs-lib@freebsd.org
Subject:   Re: cvs commit: src/lib/libc/db/hash hash_buf.c 
Message-ID:  <4131.845577674@critter.tfs.com>
In-Reply-To: Your message of "Thu, 17 Oct 1996 11:27:00 PDT." <199610171827.LAA18832@freefall.freebsd.org> 

next in thread | previous in thread | raw e-mail | index | archive | help
In message <199610171827.LAA18832@freefall.freebsd.org>, Guido van Rooij writes
:
>guido       96/10/17 11:26:59
>
>  Modified:    lib/libc/db/hash  hash_buf.c
>  Log:
>  When freeing buffers in the db routines, also zeroize them
>  This should solve the bug where a coredumping ftpd reveals
>  encrypted passwords.
>  Obtained from: OpenBSD

Isn't this a pezzimization of rank ?  I mean there are many uses of this
that do not need this...

--
Poul-Henning Kamp           | phk@FreeBSD.ORG       FreeBSD Core-team.
http://www.freebsd.org/~phk | phk@login.dknet.dk    Private mailbox.
whois: [PHK]                | phk@ref.tfs.com       TRW Financial Systems, Inc.
Future will arrive by its own means, progress not so.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4131.845577674>