DSA verification should insist that r and s are in the allowed range.
[openssl.git] / CHANGES
diff --git a/CHANGES b/CHANGES
index d85f349..c039034 100644 (file)
--- a/CHANGES
+++ b/CHANGES
          *) applies to 0.9.6a (/0.9.6b) and 0.9.7
          +) applies to 0.9.7 only
 
+  *) In dsa_do_verify (crypto/dsa/dsa_ossl.c), verify that r and s are
+     positive and less than q.
+     [Bodo Moeller]
+
   +) Enhance the general user interface with mechanisms for inner control
      and with pssibilities to have yes/no kind of prompts.
      [Richard Levitte]