Import OpenSSL-1.0.1d.
[dragonfly.git] / crypto / openssl / CHANGES
CommitLineData
56276539
SS
1
2 OpenSSL CHANGES
3 _______________
4
9bb344e0
PA
5 Changes between 1.0.1c and 1.0.1d [5 Feb 2013]
6
7 *) Make the decoding of SSLv3, TLS and DTLS CBC records constant time.
8
9 This addresses the flaw in CBC record processing discovered by
10 Nadhem Alfardan and Kenny Paterson. Details of this attack can be found
11 at: http://www.isg.rhul.ac.uk/tls/
12
13 Thanks go to Nadhem Alfardan and Kenny Paterson of the Information
14 Security Group at Royal Holloway, University of London
15 (www.isg.rhul.ac.uk) for discovering this flaw and Adam Langley and
16