X-Git-Url: https://git.distorted.org.uk/~mdw/secnet/blobdiff_plain/dd9209d1b2db57bda9123ad0c9796c79895ce187..f0b0f54918621c9a12c21c63f037471f7a961a64:/debian/changelog diff --git a/debian/changelog b/debian/changelog index 9f164bb..cabe3f9 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,20 @@ +secnet (0.3.0~beta2) unstable; urgency=low + + * New upstream version. + - SECURITY FIX: RSA public modulus and exponent buffer overflow. + - SECURITY FIX: Use constant-time memcmp for message authentication. + - SECURITY FIX: Provide a new transform, eax-serpent, to replace cbcmac. + - SECURITY FIX: No longer send NAKs for NAKs, avoiding NAK storm. + - SECURITY FIX: Fix site name checking when site name A is prefix of B. + - Better robustness for mobile sites (proper user of NAKs, new PROD msg). + - Better robustness against SLIP decoding errors. + - Fix bugs which caused routes to sometimes not be advertised. + - Protocol capability negotiation mechanism. + - Improvements and fixes to protocol and usage documentation. + - Other bugfixes and code tidying up. + + -- Ian Jackson Thu, 25 Jul 2013 18:26:01 +0100 + secnet (0.3.0~beta1) unstable; urgency=low * New upstream version.