From 563a34e18eb34f86fb26944724d4aa21ebaea850 Mon Sep 17 00:00:00 2001 From: Matt Caswell Date: Wed, 2 Nov 2016 22:27:22 +0000 Subject: [PATCH] Add a CHANGES entry for the unrecognised record type change Reviewed-by: Tim Hudson --- CHANGES | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/CHANGES b/CHANGES index 009b7ef039..1fbe3b30ed 100644 --- a/CHANGES +++ b/CHANGES @@ -4,7 +4,11 @@ Changes between 1.0.2j and 1.0.2k [xx XXX xxxx] - *) + *) OpenSSL now fails if it receives an unrecognised record type in TLS1.0 + or TLS1.1. Previously this only happened in SSLv3 and TLS1.2. This is to + prevent issues where no progress is being made and the peer continually + sends unrecognised record types, using up resources processing them. + [Matt Caswell] Changes between 1.0.2i and 1.0.2j [26 Sep 2016] -- 2.34.1