From ab1c3627b71c43c6bd8259119ac871093651f8a2 Mon Sep 17 00:00:00 2001 From: Matt Caswell Date: Tue, 17 Mar 2015 17:01:09 +0000 Subject: Update NEWS file Update the NEWS file with the latest entries from CHANGES ready for the release. Reviewed-by: Richard Levitte --- NEWS | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/NEWS b/NEWS index 2a8eb565c5..7edbb37b63 100644 --- a/NEWS +++ b/NEWS @@ -7,7 +7,13 @@ Major changes between OpenSSL 1.0.0q and OpenSSL 1.0.0r [under development] - o + o Segmentation fault in ASN1_TYPE_cmp fix (CVE-2015-0286) + o ASN.1 structure reuse memory corruption fix (CVE-2015-0287) + o PKCS7 NULL pointer dereferences fix (CVE-2015-0289) + o DoS via reachable assert in SSLv2 servers fix (CVE-2015-0293) + o Use After Free following d2i_ECPrivatekey error fix (CVE-2015-0209) + o X509_to_X509_REQ NULL pointer deref fix (CVE-2015-0288) + o Removed the export ciphers from the DEFAULT ciphers Major changes between OpenSSL 1.0.0p and OpenSSL 1.0.0q [15 Jan 2015] -- cgit v1.2.3