blob: 01fcfd7775422778d4b2dab2cecfa0353dfcebbc [file] [log] [blame] [view]
# OpenSSL Advisory: February 16th 2017 (BoringSSL Not Affected)
OpenSSL have published a [security advisory](https://www.openssl.org/news/secadv/20170216.txt). Here's how it affects BoringSSL:
CVE | Summary | [Severity] in OpenSSL | Impact to BoringSSL
----|---------|-----------------------|---------------------
CVE-2017-3733 | Encrypt-Then-Mac renegotiation crash | High | Not affected, issue introduced after fork.
[Severity]: https://openssl-library.org/policies/general/security-policy/index.html#issue-severity