X-Git-Url: https://git.openssl.org/gitweb/?p=openssl.git;a=blobdiff_plain;f=NEWS;h=82d1cb18b911c11b0dcf5b58dddd4a3638576b4b;hp=9a46c67fcf5072abbe7cc89c30ad5c16e558d985;hb=436a2a0179416d2cc22b678b63e50c2638384d5f;hpb=5105ba5bec773883e86d8c026d1eac1f1c970669 diff --git a/NEWS b/NEWS index 9a46c67fcf..82d1cb18b9 100644 --- a/NEWS +++ b/NEWS @@ -5,7 +5,24 @@ This file gives a brief overview of the major changes between each OpenSSL release. For more details please read the CHANGES file. - Major changes between OpenSSL 1.0.2h and OpenSSL 1.1.0 [in pre-release] + Major changes between OpenSSL 1.1.0a and OpenSSL 1.1.1 [under development] + + o + + Major changes between OpenSSL 1.1.0a and OpenSSL 1.1.0b [26 Sep 2016] + + o Fix Use After Free for large message sizes (CVE-2016-6309) + + Major changes between OpenSSL 1.1.0 and OpenSSL 1.1.0a [22 Sep 2016] + + o OCSP Status Request extension unbounded memory growth (CVE-2016-6304) + o SSL_peek() hang on empty record (CVE-2016-6305) + o Excessive allocation of memory in tls_get_message_header() + (CVE-2016-6307) + o Excessive allocation of memory in dtls1_preprocess_fragment() + (CVE-2016-6308) + + Major changes between OpenSSL 1.0.2h and OpenSSL 1.1.0 [25 Aug 2016] o Copyright text was shrunk to a boilerplate that points to the license o "shared" builds are now the default when possible