Fixed timing difference resulting from badly formatted padding.
diff --git a/ChangeLog b/ChangeLog
index 2689dd0..34943dc 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -4,6 +4,10 @@
 Changes
    * Allow enabling of dummy error_strerror() to support some use-cases
 
+Security
+   * Removed timing differences during SSL message decryption in
+     ssl_decrypt_buf() due to badly formatted padding
+
 = Version 1.2.4 released 2013-01-25
 Changes
    * Added ssl_handshake_step() to allow single stepping the handshake process