Extended ChangeLog entry
diff --git a/ChangeLog b/ChangeLog
index f37bd9b..e89e54a 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -4,7 +4,8 @@
 
 Security
    * Fix a potential integer underflow to buffer overread in 
-     mbedtls_rsa_rsaes_oaep_decrypt
+     mbedtls_rsa_rsaes_oaep_decrypt. It is not triggerable remotely in
+     SSL/TLS.
 
 Bugfix
    * Fix bug in mbedtls_mpi_add_mpi() that caused wrong results when the three