add security update notes
This commit is contained in:
parent
04a8eca5d3
commit
351b51613b
16
ChangeLog
16
ChangeLog
@ -31,7 +31,7 @@ LibreSSL Portable Release Notes:
|
||||
This release primarily addresses a number of security issues in coordination
|
||||
with the OpenSSL project.
|
||||
|
||||
2.2.0 - Build cleanups and OS support
|
||||
2.2.0 - Build cleanups and new OS support, Security Updates
|
||||
|
||||
* AIX Support - thanks to Michael Felt
|
||||
|
||||
@ -51,6 +51,20 @@ with the OpenSSL project.
|
||||
|
||||
* Various bug fixes and simplifications to libssl and libcrypto
|
||||
|
||||
* Fixes for the following issues are integrated into LibreSSL 2.2.0:
|
||||
- CVE-2015-1788 - Malformed ECParameters causes infinite loop
|
||||
- CVE-2015-1789 - Exploitable out-of-bounds read in X509_cmp_time
|
||||
- CVE-2015-1792 - CMS verify infinite loop with unknown hash function
|
||||
|
||||
* The following CVEs did not apply to LibreSSL or were fixed in
|
||||
earlier releases:
|
||||
- CVE-2015-4000 - DHE man-in-the-middle protection (Logjam)
|
||||
- CVE-2015-1790 - PKCS7 crash with missing EnvelopedContent
|
||||
- CVE-2014-8176 - Invalid free in DTLS
|
||||
|
||||
* Fixes for the following CVEs are still in review for LibreSSL
|
||||
- CVE-2015-1791 - Race condition handling NewSessionTicket
|
||||
|
||||
2.1.6 - Security update
|
||||
|
||||
* Fixes for the following issues are integrated into LibreSSL 2.1.6:
|
||||
|
Loading…
x
Reference in New Issue
Block a user