On 25.04.2015 20:36, Teemu Huovila wrote:
[..] http://dovecot.org/pipermail/dovecot/2015-April/100576.html I was unable to reproduce this nor the first report. Could you describe your environment in more detail? What version of openssl do you have? What is the crash message you are seeing?
Since there are three people involved I kindly ask you to be more specific as to who should provide which (exact) information.
Given you ask for it right after quoting my link all I can tell you is that I provide all the information you ask for (openssl version, crash message) in the link you quoted.
Where (openssl, distro, dovecot version) did you try reproducing it? I've asked a friend using debian or centos (don't know which) and he was unable to reproduce so as always they might be patching something, it might not affect old software or they don't link with openssl.
I also provide a link to an openssl dev explaining why this happens later in my thread. Here's the openssl bug report about this issue: https://rt.openssl.org/Ticket/Display.html?id=3818. Login for the openssl tracker is guest/guest.