[Pkg-openssl-devel] Bug#758197: libssl-dev: libssl segfaults when called SSL_CTX_new(SSLv23_client_method()).

Dariusz Dwornikowski dariusz.dwornikowski at cs.put.poznan.pl
Fri Aug 15 10:04:19 UTC 2014


Package: libssl-dev
Version: 1.0.1i-2
Severity: normal

Dear Maintainer,

When calling SSL_CTX_new(SSLv23_client_method()), libssl crashes with stack
smash detected. After some time debugging with gdb, I have pinpointed that this
happens in ssleay_rand_add function in md_rand.c.

I encountered the problem when packaging libstrophe for Debian. In Jessie it
crashes, whereas on different systems (Ubuntu) it does not.

I can provide more information if needed.





-- System Information:
Debian Release: jessie/sid
  APT prefers testing
  APT policy: (650, 'testing'), (600, 'unstable'), (500, 'testing-updates')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.14-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=pl_PL.UTF-8, LC_CTYPE=pl_PL.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages libssl-dev depends on:
ii  libssl1.0.0  1.0.1i-2
ii  zlib1g-dev   1:1.2.8.dfsg-1

Versions of packages libssl-dev recommends:
ii  libssl-doc  1.0.1i-1

libssl-dev suggests no packages.

-- no debconf information

-- 
Dariusz Dwornikowski, 
  Institute of Computing Science, Poznań University of Technology
  www.cs.put.poznan.pl/ddwornikowski/  
  room 2.7.2 BTiCW | tel. +48 61 665 29 41



More information about the Pkg-openssl-devel mailing list