openssl/crypto/ec
Bernd Edlinger 202f7c5659 Clear the point S before freeing in ec_scalar_mul_ladder
The secret point R can be recovered from S using the equation R = S - P.
The X and Z coordinates should be sufficient for that.

Reviewed-by: Paul Dale <paul.dale@oracle.com>
(Merged from https://github.com/openssl/openssl/pull/8504)

(cherry picked from commit 8a74bb5c7b)
2019-03-18 22:42:23 +01:00
..
asm Update copyright year 2019-02-26 14:05:09 +00:00
curve448 fix truncation of integers on 32bit AIX 2019-03-11 14:47:00 +01:00
build.info Add ec/asm/x25519-ppc64.pl module. 2018-07-26 14:01:49 +02:00
curve25519.c curve25519.c: improve formula alignment 2018-12-06 20:55:00 +01:00
ec2_oct.c Update copyright year 2018-09-11 13:45:17 +01:00
ec2_smpl.c SCA hardening for mod. field inversion in EC_GROUP 2019-02-20 19:54:19 +02:00
ec_ameth.c Fix the default digest algorthm of SM2 2019-02-27 10:09:54 +08:00
ec_asn1.c Use the new non-curve type specific EC functions internally 2018-07-31 09:08:38 +01:00
ec_check.c
ec_curve.c Use the new non-curve type specific EC functions internally 2018-07-31 09:08:38 +01:00
ec_cvt.c Update copyright year 2018-09-11 13:45:17 +01:00
ec_err.c SCA hardening for mod. field inversion in EC_GROUP 2019-02-20 19:54:19 +02:00
ec_key.c Fix segfault in RSA_free() (and DSA/DH/EC_KEY) 2018-09-05 15:22:35 +03:00
ec_kmeth.c Update copyright year 2018-09-11 13:45:17 +01:00
ec_lcl.h Rearrange the inclusion of curve448/curve448_lcl.h 2019-02-25 19:37:01 +01:00
ec_lib.c [test] throw error from wrapper function instead of an EC_METHOD specific one 2018-09-03 20:25:41 +02:00
ec_mult.c Clear the point S before freeing in ec_scalar_mul_ladder 2019-03-18 22:42:23 +01:00
ec_oct.c Deprecate the EC curve type specific functions in 1.2.0 2018-07-31 09:08:50 +01:00
ec_pmeth.c EVP module documentation pass 2018-10-17 13:31:59 +03:00
ec_print.c Update copyright year 2018-04-17 15:18:40 +02:00
ecdh_kdf.c EVP module documentation pass 2018-10-17 13:31:59 +03:00
ecdh_ossl.c Clear the secret point in ecdh_simple_compute_key 2019-03-18 22:30:50 +01:00
ecdsa_ossl.c Use the new non-curve type specific EC functions internally 2018-07-31 09:08:38 +01:00
ecdsa_sign.c Useless includes 2016-06-18 16:30:24 -04:00
ecdsa_vrf.c Useless includes 2016-06-18 16:30:24 -04:00
eck_prn.c Update copyright year 2018-09-11 13:45:17 +01:00
ecp_mont.c SCA hardening for mod. field inversion in EC_GROUP 2019-02-20 19:54:19 +02:00
ecp_nist.c SCA hardening for mod. field inversion in EC_GROUP 2019-02-20 19:54:19 +02:00
ecp_nistp224.c SCA hardening for mod. field inversion in EC_GROUP 2019-02-20 19:54:19 +02:00
ecp_nistp256.c SCA hardening for mod. field inversion in EC_GROUP 2019-02-20 19:54:19 +02:00
ecp_nistp521.c Avoid an underflow in ecp_nistp521.c 2019-03-07 14:47:39 +00:00
ecp_nistputil.c
ecp_nistz256.c SCA hardening for mod. field inversion in EC_GROUP 2019-02-20 19:54:19 +02:00
ecp_nistz256_table.c
ecp_oct.c Update copyright year 2018-09-11 13:45:17 +01:00
ecp_smpl.c SCA hardening for mod. field inversion in EC_GROUP 2019-02-20 19:54:19 +02:00
ecx_meth.c Update copyright year 2019-02-26 14:05:09 +00:00