From d3403d1e015277d9d1b48a0c21c35d32ff934cd6 Mon Sep 17 00:00:00 2001 From: Frank Denis Date: Fri, 15 Aug 2014 13:21:09 -0700 Subject: [PATCH] memzero az in crypto_signed_detached. via Stanford SCS. --- src/libsodium/crypto_sign/ed25519/ref10/sign.c | 1 + 1 file changed, 1 insertion(+) diff --git a/src/libsodium/crypto_sign/ed25519/ref10/sign.c b/src/libsodium/crypto_sign/ed25519/ref10/sign.c index 604bad9b..c56367df 100644 --- a/src/libsodium/crypto_sign/ed25519/ref10/sign.c +++ b/src/libsodium/crypto_sign/ed25519/ref10/sign.c @@ -45,6 +45,7 @@ crypto_sign_detached(unsigned char *sig, unsigned long long *siglen, sc_reduce(hram); sc_muladd(sig + 32, hram, az, nonce); + sodium_memzero(az, sizeof az); sodium_memzero(nonce, sizeof nonce); if (siglen != NULL) {