Modify changelog entry to add pkcs12 pbe functions

Signed-off-by: Waleed Elmelegy <waleed.elmelegy@arm.com>
This commit is contained in:
Waleed Elmelegy 2023-09-13 13:35:16 +01:00
parent 57d09b72ef
commit 0684965f5a

View File

@ -1,6 +1,7 @@
Security Security
* Developers using mbedtls_pkcs5_pbes2() should review the size of the output * Developers using mbedtls_pkcs5_pbes2() or mbedtls_pkcs12_pbe() should review
buffer passed to this function, and note that the output after decryption the size of the output buffer passed to this function, and note that the
may include CBC padding. Consider moving to the new function output after decryption may include CBC padding. Consider moving to the
mbedtls_pkcs5_pbes2_ext() which checks for overflow of the output buffer new functions mbedtls_pkcs5_pbes2_ext() or mbedtls_pkcs12_pbe_ext() which
and reports the actual length of the output. checks for overflow of the output buffer and reports the actual length
of the output.