More length checks in RSA PKCS1v15 verify
Tighten ASN.1 parsing of RSA PKCS#1 v1.5 signatures, to avoid a
potential Bleichenbacher-style attack.
Backport to 2.1.x
diff --git a/ChangeLog b/ChangeLog
index fe5ce65..a6e1fbd 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,5 +1,11 @@
mbed TLS ChangeLog (Sorted per branch, date)
+= mbed TLS 2.1.x branch released xxxx-xx-xx
+
+Security
+ * Tighten ASN.1 parsing of RSA PKCS#1 v1.5 signatures, to avoid a
+ potential Bleichenbacher-style attack.
+
= mbed TLS 2.1.7 branch released 2017-03-08
Security