X-Git-Url: https://git.openssl.org/gitweb/?a=blobdiff_plain;f=NEWS;h=1d81d4ccf359906cc57f8dd6b7f2135def118e92;hb=83d6620986ab351b02ec2f5bbc30d2c4cac21f63;hp=74767da16bcdf071acfd43b76c16423e68ce65e8;hpb=82123b5e9415d336a0d15efcaae1b52683fa00e7;p=openssl.git diff --git a/NEWS b/NEWS index 74767da16b..1d81d4ccf3 100644 --- a/NEWS +++ b/NEWS @@ -5,10 +5,32 @@ This file gives a brief overview of the major changes between each OpenSSL release. For more details please read the CHANGES file. - Major changes between OpenSSL 1.0.1l and OpenSSL 1.0.1m [under development] + Major changes between OpenSSL 1.0.1o and OpenSSL 1.0.1p [under development] o + Major changes between OpenSSL 1.0.1n and OpenSSL 1.0.1o [12 Jun 2015] + + o Fix HMAC ABI incompatibility + + Major changes between OpenSSL 1.0.1m and OpenSSL 1.0.1n [11 Jun 2015] + + o Malformed ECParameters causes infinite loop (CVE-2015-1788) + o Exploitable out-of-bounds read in X509_cmp_time (CVE-2015-1789) + o PKCS7 crash with missing EnvelopedContent (CVE-2015-1790) + o CMS verify infinite loop with unknown hash function (CVE-2015-1792) + o Race condition handling NewSessionTicket (CVE-2015-1791) + + Major changes between OpenSSL 1.0.1l and OpenSSL 1.0.1m [19 Mar 2015] + + o Segmentation fault in ASN1_TYPE_cmp fix (CVE-2015-0286) + o ASN.1 structure reuse memory corruption fix (CVE-2015-0287) + o PKCS7 NULL pointer dereferences fix (CVE-2015-0289) + o DoS via reachable assert in SSLv2 servers fix (CVE-2015-0293) + o Use After Free following d2i_ECPrivatekey error fix (CVE-2015-0209) + o X509_to_X509_REQ NULL pointer deref fix (CVE-2015-0288) + o Removed the export ciphers from the DEFAULT ciphers + Major changes between OpenSSL 1.0.1k and OpenSSL 1.0.1l [15 Jan 2015] o Build fixes for the Windows and OpenVMS platforms