From: Niels Möller Date: Wed, 2 Jun 2021 19:04:13 +0000 (+0200) Subject: Update Nettle-3.7.3 NEWS, and credit Paul Schaub. X-Git-Tag: nettle_3.7.3_release_20210606^0 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=refs%2Fheads%2Frelease-3.7-fixes;p=thirdparty%2Fnettle.git Update Nettle-3.7.3 NEWS, and credit Paul Schaub. --- diff --git a/NEWS b/NEWS index 277ef383..4a55da8f 100644 --- a/NEWS +++ b/NEWS @@ -9,7 +9,8 @@ NEWS for the Nettle 3.7.3 release ciphertext is in the range 0 < ciphertext < n, before attempting to decrypt it. - Thanks to Justus Winter for reporting these problems. + Thanks to Paul Schaub and Justus Winter for reporting these + problems. The new version is intended to be fully source and binary compatible with Nettle-3.6. The shared library names are @@ -26,8 +27,8 @@ NEWS for the Nettle 3.7.3 release or silently reducing input modulo n. Potential denial of service vector. - * Ensure that all of rsa_decrypt returns failure for out of - range inputs, instead of silently reducing input modulo n. + * Ensure that rsa_decrypt returns failure for out of range + inputs, instead of silently reducing input modulo n. * Ensure that rsa_sec_decrypt returns failure if the message size is too large for the given key. Unlike the other bugs,