Re: Malloc -Z

看板FB_security作者時間14年前 (2011/07/28 02:32), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串6/9 (看更多)
On Wed, 27 Jul 2011 02:49:48 -0400 grarpamp wrote: > Was reading malloc(3) while chasing corruption suspects. > Does the presence of -Z imply that without it, programs > can be allocated dirty (non-zeroed) memory? Programs (in the sense of processes) are allocated zeroed-memory. Memory allocated by malloc will either be zeroed or contain pages written to by the same process. In general any security concerns about sensitive data should be handled by zeroing before freeing (or when the data is no longer needed) rather than zeroing on allocation. _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #1EC5cYYw (FB_security)
文章代碼(AID): #1EC5cYYw (FB_security)