Commit | Line | Data |
---|---|---|
56276539 SS |
1 | |
2 | OpenSSL CHANGES | |
3 | _______________ | |
4 | ||
9bb344e0 PA |
5 | Changes between 1.0.1c and 1.0.1d [5 Feb 2013] |
6 | ||
7 | *) Make the decoding of SSLv3, TLS and DTLS CBC records constant time. | |
8 | ||
9 | This addresses the flaw in CBC record processing discovered by | |
10 | Nadhem Alfardan and Kenny Paterson. Details of this attack can be found | |
11 | at: http://www.isg.rhul.ac.uk/tls/ | |
12 | ||
13 | Thanks go to Nadhem Alfardan and Kenny Paterson of the Information | |
14 | Security Group at Royal Holloway, University of London | |
15 | (www.isg.rhul.ac.uk) for discovering this flaw and Adam Langley and | |
16 |