mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2026-07-30 16:26:33 +08:00
Update ChangeLog
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
This commit is contained in:
parent
d32397563e
commit
835226c59a
@ -4,10 +4,9 @@ Security
|
||||
handshake to fail. This could allow a handshake to continue with a master
|
||||
secret that was not correctly bound to the handshake transcript,
|
||||
undermining the security guarantees of the extended master secret
|
||||
extension. Report by Mathew Gretton-Dann
|
||||
extension. Report by Mathew Gretton-Dann.
|
||||
* Fix a bug where TLS 1.3 servers could ignore errors when computing the
|
||||
resumption master secret instead of causing the handshake to fail. This
|
||||
could allow a server to issue resumption tickets derived from an invalid
|
||||
resumption secret, weakening authentication of future resumptions made
|
||||
with those tickets. Reported by jjfz123 / https://github.com/jjfz123 /
|
||||
https://www.linkedin.com/in/jjfdzcastro1/
|
||||
with those tickets. Reported by jjfz123.
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user