Since commit 74a308cf5221f we use explicit_bzero on pgpass and connhost password in libpq, but not sslpassword which seems an oversight. The attached performs an explicit_bzero before freeing like the pattern for other password variables.
cheers ./daniel
sslpassword_bzero.patch
Description: Binary data