On Tue, Feb 02, 2016 at 03:28:43PM +0000, Kevin Chadwick wrote:
> > This impact all users who upgrade to OpenSSL 1.0.2f and will cause smtpd
> > to crash as soon as the RSA engine is used (ie: whenever there's crypto)
> > 
> > A quick workaround is to not upgrade to 1.0.2f yet and maybe ask OpenSSL
> > why a "patchlevel" release contains more than patches.
> > 
> > Meanwhile, we're investigating how we're going to unfuck this.
> 
> Does this affect other projects? I am simply wondering what the odds
> are of this being hostility or stupidity?
> 

An OpenSSL developer who wasn't aware I already had the fix contacted me
this night to let me know what was causing the crash. That does not seem
very hostile to me ;-)

I think it is unfortunate that they slipped an API change, even a subtle
one, in a patch release that people were kind of obligated to apply, but
this is more of a releng issue IMO.

-- 
Gilles Chehade

https://www.poolp.org                                          @poolpOrg

-- 
You received this mail because you are subscribed to [email protected]
To unsubscribe, send a mail to: [email protected]

Reply via email to