From 9d67ca251cf6421bbf34062ff6294833b43a226f Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Thu, 31 Oct 2019 10:06:00 +0100 Subject: [PATCH] SSH-01-012: Fix information leak via uninitialized stack buffer Fixes T190 Signed-off-by: Andreas Schneider Reviewed-by: Jakub Jelen --- src/pki_container_openssh.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/pki_container_openssh.c b/src/pki_container_openssh.c index 5ad87b53..114459a4 100644 --- a/src/pki_container_openssh.c +++ b/src/pki_container_openssh.c @@ -108,8 +108,8 @@ static int pki_private_key_decrypt(ssh_string blob, { struct ssh_cipher_struct *ciphers = ssh_get_ciphertab(); struct ssh_cipher_struct cipher; - uint8_t key_material[128]; - char passphrase_buffer[128]; + uint8_t key_material[128] = {0}; + char passphrase_buffer[128] = {0}; size_t key_material_len; ssh_buffer buffer; ssh_string salt;