Fix 1 byte overread in mbedtls_asn1_get_int()
diff --git a/ChangeLog b/ChangeLog
index 61603c7..2609aee 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -10,7 +10,10 @@
      when GCM is used. #441
    * Fix for key exchanges based on ECDH-RSA or ECDH-ECDSA which weren't
      enabled unless others were also present. Found by David Fernandez. #428
-   * Fixed configuration of debug output in cert_app sample program.
+   * Fixed cert_app sample program for debug output and for use when no root
+     certificates are provided.
+   * Fix conditional statement that would cause a 1 byte overread in
+     mbedtls_asn1_get_int(). Found and fixed by Guido Vranken.
    * Fixed the sample applications gen_key.c, cert_req.c and cert_write.c for
      builds where the configuration POLARSSL_PEM_WRITE_C is not defined. Found
      by inestlerode. #559.