mbedtls/ChangeLog.d/tls13-only-server-infinite-loop.txt
Ronald Cron e301813da4 Improve change log
Signed-off-by: Ronald Cron <ronald.cron@arm.com>
2024-03-07 09:10:22 +01:00

6 lines
279 B
Plaintext

Security
* Fixed a denial of service in TLS 1.3-only server (TLS 1.2 support
disabled at build time): a TLS client could put the TLS 1.3-only server in
an infinite loop processing a TLS 1.2 ClientHello. Reported by Matthias
Mucha and Thomas Blattmann, SICK AG.