Add ChangeLog entries for pk_parse_key() fixes

This commit is contained in:
Manuel Pégourié-Gonnard 2020-02-19 09:31:38 +01:00
parent d09fcdedb9
commit 6444d1557d

View File

@ -17,6 +17,11 @@ Security
Bugfix Bugfix
* Fix an unchecked call to mbedtls_md() in the x509write module. * Fix an unchecked call to mbedtls_md() in the x509write module.
* Fix a bug in mbedtls_pk_parse_key() that would cause it to accept some
RSA keys that would later be rejected by functions expecting private
keys. Found by Catena cyber using oss-fuzz (issue 20467).
* Fix a bug in mbedtls_pk_parse_key() that would cause it to accept some
RSA keys with invalid values by silently fixing those values.
= mbed TLS 2.16.4 branch released 2020-01-15 = mbed TLS 2.16.4 branch released 2020-01-15