]> git.ipfire.org Git - thirdparty/curl.git/commitdiff
ntlm: clear lm and nt response buffers before use
authorDaniel Stenberg <daniel@haxx.se>
Wed, 22 Mar 2023 12:31:11 +0000 (13:31 +0100)
committerDaniel Stenberg <daniel@haxx.se>
Thu, 23 Mar 2023 08:25:05 +0000 (09:25 +0100)
To avoid the risk of MemorySanitizer: use-of-uninitialized-value

Closes #10814

lib/vauth/ntlm.c

index 2a5d4a4908fcb377ff81400e03c743d7baefe706..5aa7e6ec0058f0c9049f0f19fc8b5ddd564e9e1e 100644 (file)
@@ -511,6 +511,8 @@ CURLcode Curl_auth_create_ntlm_type3_message(struct Curl_easy *data,
   size_t userlen = 0;
   size_t domlen = 0;
 
+  memset(lmresp, 0, sizeof(lmresp));
+  memset(ntresp, 0, sizeof(ntresp));
   user = strchr(userp, '\\');
   if(!user)
     user = strchr(userp, '/');