summaryrefslogtreecommitdiff
path: root/NEWS
diff options
context:
space:
mode:
authorMatt Caswell <matt@openssl.org>2016-11-10 11:49:06 +0000
committerMatt Caswell <matt@openssl.org>2016-11-10 13:04:11 +0000
commit6a69e8694af23dae1d1927813932f4296d133416 (patch)
tree009a9b7299ccfe59e5fca0a5899ef8d57350d7bb /NEWS
parentf07d639edf849413e24845301fd514ff4a606000 (diff)
downloadopenssl-new-6a69e8694af23dae1d1927813932f4296d133416.tar.gz
Update CHANGES and NEWS
Reviewed-by: Richard Levitte <levitte@openssl.org>
Diffstat (limited to 'NEWS')
-rw-r--r--NEWS3
1 files changed, 3 insertions, 0 deletions
diff --git a/NEWS b/NEWS
index 82d1cb18b9..e88c5f470b 100644
--- a/NEWS
+++ b/NEWS
@@ -11,6 +11,9 @@
Major changes between OpenSSL 1.1.0a and OpenSSL 1.1.0b [26 Sep 2016]
+ o ChaCha20/Poly1305 heap-buffer-overflow (CVE-2016-7054)
+ o CMS Null dereference (CVE-2016-7053)
+ o Montgomery multiplication may produce incorrect results (CVE-2016-7055)
o Fix Use After Free for large message sizes (CVE-2016-6309)
Major changes between OpenSSL 1.1.0 and OpenSSL 1.1.0a [22 Sep 2016]