Package: libsqlcipher0
Version: 3.2.0-2
Followup-For: Bug #863530

Dear Maintainer,

the OpenSSL 1.1.x compatability patch that was applied for #828555 breaks the 
package and leads to segfaults.
This breaks skrooge and other applications depending on libsqlcipher0.

I diffed src/crypto_openssl.c against the most current version (3.4.1) and 
noticed the switch to the non-deprecated API function around EVP_CipherInit_ex 
instead of EVP_CipherInit.
I ported these differences to 3.2.0-2, recompiled the package from Debian 
sources including my patch. The resulting binaries no longer produce segfaults 
and work as expected.
This is in line with release 3.4.1-1 on sid.

You can find the patch at http://paste.debian.net/998532/

Please review the patch and include it in stable.

Kind regards,
Philipp


-- System Information:
Debian Release: 9.1
  APT prefers stable
  APT policy: (890, 'stable'), (500, 'stable-updates'), (200, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 4.9.0-4-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages libsqlcipher0 depends on:
ii  libc6      2.24-11+deb9u1
ii  libssl1.1  1.1.0f-3+deb9u1

libsqlcipher0 recommends no packages.

libsqlcipher0 suggests no packages.

-- no debconf information

Reply via email to