Backport 1.3: check if iv is zero in gcm.

1) found by roberto in mbedtls forum
2) if iv_len is zero, return an error
3) add tests for invalid parameters
diff --git a/ChangeLog b/ChangeLog
index 1672bdf..8493885 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,6 +1,12 @@
 mbed TLS ChangeLog (Sorted per branch, date)
 
-= mbed TLS 1.3.20 released 2017-06-21
+= mbed TLS 1.3.21 branch released xxxx-xx-xx
+
+Bugfix
+   * Add a check if iv_len is zero, and return an error if it is zero. reported
+     by roberto. #716
+
+= mbed TLS 1.3.20 branch released 2017-06-21
 
 Security
    * Fixed unlimited overread of heap-based buffer in ssl_read().