Add precision about exploitability in ChangeLog

Also fix some whitespace while at it.
diff --git a/ChangeLog b/ChangeLog
index 113acd5..78ce7f9 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -10,6 +10,7 @@
      required by PKCS1 v2.2
    * Fix potential integer overflow to buffer overflow in
      mbedtls_rsa_rsaes_pkcs1_v15_encrypt and mbedtls_rsa_rsaes_oaep_encrypt
+     (not triggerable remotely in (D)TLS).
 
 Bugfix
    * Fix bug in mbedtls_mpi_add_mpi() that caused wrong results when the three