Update CHANGES, reference a CVE.
diff --git a/CHANGES b/CHANGES
index 2de91c9..a06b0ed 100644
--- a/CHANGES
+++ b/CHANGES
@@ -10,6 +10,7 @@
 
       Note: This fixes a security issue with a potential leak of data contained
       on the destroyed node which only affects users of the DigitalOcean driver.
+      (CVE-2013-6480)
       [Tomaz Muraus]
 
 Changes with Apache Libcloud 0.13.2