update NEWS
authorDr. Stephen Henson <steve@openssl.org>
Wed, 6 Aug 2014 13:47:50 +0000 (14:47 +0100)
committerMatt Caswell <matt@openssl.org>
Wed, 6 Aug 2014 19:33:25 +0000 (20:33 +0100)
Reviewed-by: Kurt Roeckx <kurt@openssl.org>
NEWS

diff --git a/NEWS b/NEWS
index 02f8a55772088b756d3e5c472bcd67d5b7211747..07d7602aaaeb6a609bdd24b64db2ba9111225af8 100644 (file)
--- a/NEWS
+++ b/NEWS
@@ -7,12 +7,15 @@
 
   Major changes between OpenSSL 1.0.1h and OpenSSL 1.0.1i [under development]
 
-      o
-
-  Known issues in OpenSSL 1.0.1h:
-
-      o EAP-FAST and other applications using tls_session_secret_cb
-        wont resume sessions. Fixed in 1.0.1i-dev
+      o Fix for CVE-2014-3512
+      o Fix for CVE-2014-3511
+      o Fix for CVE-2014-3510
+      o Fix for CVE-2014-3507
+      o Fix for CVE-2014-3506
+      o Fix for CVE-2014-3505
+      o Fix for CVE-2014-3509
+      o Fix for CVE-2014-5139
+      o Fix for CVE-2014-3508
 
   Major changes between OpenSSL 1.0.1g and OpenSSL 1.0.1h [5 Jun 2014]