From bedc728fedfeb8d5b13cde7cad0bd1c279bfcd7a Mon Sep 17 00:00:00 2001 From: Janos Follath Date: Wed, 10 Feb 2016 16:25:55 +0000 Subject: [PATCH] Add Changelog entry for current branch --- ChangeLog | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/ChangeLog b/ChangeLog index e54e74c18..aef64c11e 100644 --- a/ChangeLog +++ b/ChangeLog @@ -9,6 +9,10 @@ Security mbedtls_rsa_rsaes_oaep_decrypt. It is not triggerable remotely in SSL/TLS. +Security + * Fix potential integer overflow to buffer overflow in + mbedtls_rsa_rsaes_pkcs1_v15_encrypt and mbedtls_rsa_rsaes_oaep_encrypt + Bugfix * Fix bug in mbedtls_mpi_add_mpi() that caused wrong results when the three arguments where the same (in-place doubling). Found and fixed by Janos