From b67802c2db673f970b2421998e97a4755813acc9 Mon Sep 17 00:00:00 2001 From: Brent Cook Date: Fri, 23 Sep 2016 05:43:04 -0500 Subject: update changelog for 2.3.8 --- ChangeLog | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/ChangeLog b/ChangeLog index 6687e5b..c96bd4c 100644 --- a/ChangeLog +++ b/ChangeLog @@ -28,6 +28,15 @@ history is also available from Git. LibreSSL Portable Release Notes: +2.3.8 - Security and reliability fixes + + * Avoid unbounded memory growth in libssl, which can be triggered by a + TLS client repeatedly renegotiating and sending OCSP Status Request + TLS extensions. + + * Avoid falling back to a weak digest for (EC)DH when using SNI with + libssl. + 2.3.7 - OCSP fixes * Fix several issues in the OCSP code that could result in the -- cgit v1.2.3-55-g6feb