Merge branch 'development-restricted' into prepare-rc-2.22.0-updated

* development-restricted:
  Parse HelloVerifyRequest buffer overread: add changelog entry
  Parse HelloVerifyRequest: avoid buffer overread at the start
  Parse HelloVerifyRequest: avoid buffer overread on the cookie
This commit is contained in:
Manuel Pégourié-Gonnard
2020-04-09 12:17:11 +02:00
2 changed files with 16 additions and 2 deletions
+2
View File
@@ -18,6 +18,8 @@ Security
untrusted operating system attacking a secure enclave) to fully recover
an ECDSA private key. Found and reported by Alejandro Cabrera Aldaya,
Billy Brumley and Cesar Pereida Garcia. CVE-2020-10932
* Fix a potentially remotely exploitable buffer overread in a
DTLS client when parsing the Hello Verify Request message.
Features
* The new build option MBEDTLS_SSL_VARIABLE_BUFFER_LENGTH automatically