Prevent malformed RFC3779 data triggering an assertion failure (CVE-2011-4577)
[openssl.git] / CHANGES
diff --git a/CHANGES b/CHANGES
index 9d7575a2a002aa96085d01683ec14bbb468325fa..7c31eadb7a1f93fe380b76bed5f828ffc0bd9b60 100644 (file)
--- a/CHANGES
+++ b/CHANGES
   *) Add support for SCTP.
      [Robin Seggelmann <seggelmann@fh-muenster.de>]
 
   *) Add support for SCTP.
      [Robin Seggelmann <seggelmann@fh-muenster.de>]
 
+  *) Prevent malformed RFC3779 data triggering an assertion failure.
+     Thanks to Andrew Chi, BBN Technologies, for discovering the flaw
+     and Rob Austein <sra@hactrn.net> for fixing it. (CVE-2011-4577)
+     [Rob Austein <sra@hactrn.net>]
+
   *) Improved PRNG seeding for VOS.
      [Paul Green <Paul.Green@stratus.com>]
 
   *) Improved PRNG seeding for VOS.
      [Paul Green <Paul.Green@stratus.com>]