Corrected GCM counter incrementation to use only 32-bits instead of 128-bits
Using 32-bits has the possibility to overwrite the IV in the first 12
bytes of the Y variable.
Found by Yawning Angel
diff --git a/ChangeLog b/ChangeLog
index 75989bb..a5fc141 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -3,6 +3,8 @@
= Master
Bugfix
* Fixed memory leak in ssl_free() and ssl_reset() for active session
+ * Corrected GCM counter incrementation to use only 32-bits instead of
+ 128-bits (found by Yawning Angel)
Security
* Removed further timing differences during SSL message decryption in