Clear static buffer returned by getpass()

This commit is contained in:
Tobias Brunner
2021-10-04 11:30:03 +02:00
parent de442491d9
commit 128d054407
4 changed files with 5 additions and 2 deletions
+1
View File
@@ -112,6 +112,7 @@ static shared_key_t* callback_shared(private_cmd_creds_t *this,
*match_other = ID_MATCH_PERFECT; *match_other = ID_MATCH_PERFECT;
} }
shared = shared_key_create(type, chunk_clone(chunk_from_str(pwd))); shared = shared_key_create(type, chunk_clone(chunk_from_str(pwd)));
memwipe(pwd, strlen(pwd));
/* cache password in case it is required more than once */ /* cache password in case it is required more than once */
this->creds->add_shared(this->creds, shared, NULL); this->creds->add_shared(this->creds, shared, NULL);
return shared->get_ref(shared); return shared->get_ref(shared);
+1
View File
@@ -393,6 +393,7 @@ static shared_key_t* cb(void *data, shared_key_type_t type,
*match_other = ID_MATCH_NONE; *match_other = ID_MATCH_NONE;
} }
shared = shared_key_create(type, chunk_clone(chunk_from_str(secret))); shared = shared_key_create(type, chunk_clone(chunk_from_str(secret)));
memwipe(secret, strlen(secret));
/* cache password in case it is required more than once */ /* cache password in case it is required more than once */
cb_creds->add_shared(cb_creds, shared, NULL); cb_creds->add_shared(cb_creds, shared, NULL);
return shared->get_ref(shared); return shared->get_ref(shared);
+1
View File
@@ -129,6 +129,7 @@ static int send_stroke_msg(stroke_msg_t *msg)
if (pass) if (pass)
{ {
stream->write_all(stream, pass, strlen(pass)); stream->write_all(stream, pass, strlen(pass));
memwipe(pass, strlen(pass));
stream->write_all(stream, "\n", 1); stream->write_all(stream, "\n", 1);
} }
} }
+2 -2
View File
@@ -254,6 +254,7 @@ CALLBACK(password_cb, shared_key_t*,
*match_other = ID_MATCH_PERFECT; *match_other = ID_MATCH_PERFECT;
} }
shared = shared_key_create(type, chunk_clone(chunk_from_str(pwd))); shared = shared_key_create(type, chunk_clone(chunk_from_str(pwd)));
memwipe(pwd, strlen(pwd));
/* cache secret if it is required more than once (PKCS#12) */ /* cache secret if it is required more than once (PKCS#12) */
data->cache->add_shared(data->cache, shared, NULL); data->cache->add_shared(data->cache, shared, NULL);
return shared->get_ref(shared); return shared->get_ref(shared);
@@ -635,14 +636,13 @@ static void load_tokens(load_ctx_t *ctx)
{ {
#ifdef HAVE_GETPASS #ifdef HAVE_GETPASS
snprintf(prompt, sizeof(prompt), "PIN for %s: ", section); snprintf(prompt, sizeof(prompt), "PIN for %s: ", section);
pin = strdupnull(getpass(prompt)); pin = getpass(prompt);
#endif #endif
} }
load_token(ctx, section, pin); load_token(ctx, section, pin);
if (pin) if (pin)
{ {
memwipe(pin, strlen(pin)); memwipe(pin, strlen(pin));
free(pin);
pin = NULL; pin = NULL;
} }
} }