X-Git-Url: https://git.openssl.org/?p=openssl.git;a=blobdiff_plain;f=NEWS;h=02f8a55772088b756d3e5c472bcd67d5b7211747;hp=909fea96cf7484691ded28286e2f84cdf7949077;hb=966fe81f9befbff62522a158006fb03050a868df;hpb=0d8776344cd7965fadd870e361503985df9c45bb diff --git a/NEWS b/NEWS index 909fea96cf..02f8a55772 100644 --- a/NEWS +++ b/NEWS @@ -5,8 +5,33 @@ This file gives a brief overview of the major changes between each OpenSSL release. For more details please read the CHANGES file. + Major changes between OpenSSL 1.0.1h and OpenSSL 1.0.1i [under development] + + o + + Known issues in OpenSSL 1.0.1h: + + o EAP-FAST and other applications using tls_session_secret_cb + wont resume sessions. Fixed in 1.0.1i-dev + + Major changes between OpenSSL 1.0.1g and OpenSSL 1.0.1h [5 Jun 2014] + + o Fix for CVE-2014-0224 + o Fix for CVE-2014-0221 + o Fix for CVE-2014-0198 + o Fix for CVE-2014-0195 + o Fix for CVE-2014-3470 + o Fix for CVE-2010-5298 + + Major changes between OpenSSL 1.0.1f and OpenSSL 1.0.1g [7 Apr 2014] + + o Fix for CVE-2014-0160 + o Add TLS padding extension workaround for broken servers. + o Fix for CVE-2014-0076 + Major changes between OpenSSL 1.0.1e and OpenSSL 1.0.1f [6 Jan 2014] + o Don't include gmt_unix_time in TLS server and client random values o Fix for TLS record tampering bug CVE-2013-4353 o Fix for TLS version checking bug CVE-2013-6449 o Fix for DTLS retransmission bug CVE-2013-6450