mirror of
https://github.com/cuberite/polarssl.git
synced 2025-09-23 04:26:46 -04:00
Keep only the X.509 part from the Changelog
Signed-off-by: Manuel Pégourié-Gonnard <manuel.pegourie-gonnard@arm.com>
This commit is contained in:
parent
5f6310b65f
commit
dc82fa67c5
@ -1,12 +1,8 @@
|
||||
Security
|
||||
* Fix a bug in mbedtls_asn1_store_named_data() where it would sometimes leave
|
||||
an item in the output list in an inconsistent state with val.p == NULL but
|
||||
val.len > 0. This impacts applications that call this function directly,
|
||||
or indirectly via mbedtls_x509_string_to_names() or one of the
|
||||
mbedtls_x509write_{crt,csr}_set_{subject,issuer}_name() functions. The
|
||||
inconsistent state of the output could then cause a NULL dereference either
|
||||
inside the same call to mbedtls_x509_string_to_names(), or in subsequent
|
||||
* Fix a bug in mbedtls_x509_string_to_names() and the
|
||||
mbedtls_x509write_{crt,csr}_set_{subject,issuer}_name() functions,
|
||||
where some inputs would cause an inconsistent state to be reached, causing
|
||||
a NULL dereference either in the function itself, or in subsequent
|
||||
users of the output structure, such as mbedtls_x509_write_names(). This
|
||||
only affects applications that create (as opposed to consume) X.509
|
||||
certificates, CSRs or CRLS, or that call mbedtls_asn1_store_named_data()
|
||||
directly. Found by Linh Le and Ngan Nguyen from Calif.
|
||||
certificates, CSRs or CRLs. Found by Linh Le and Ngan Nguyen from Calif.
|
||||
|
Loading…
x
Reference in New Issue
Block a user