GNU bug report logs - #27462
OCaml CVE-2015-8869

Previous Next

Package: guix;

Reported by: Leo Famulari <leo <at> famulari.name>

Date: Fri, 23 Jun 2017 16:42:02 UTC

Severity: normal

Tags: security

Done: Julien Lepiller <julien <at> lepiller.eu>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: help-debbugs <at> gnu.org (GNU bug Tracking System)
To: Julien Lepiller <julien <at> lepiller.eu>
Cc: tracker <at> debbugs.gnu.org
Subject: bug#27462: closed (OCaml CVE-2015-8869 )
Date: Fri, 05 Jul 2019 12:13:01 +0000
[Message part 1 (text/plain, inline)]
Your message dated Fri, 05 Jul 2019 14:12:56 +0200
with message-id <5E92B59E-1D62-498E-BBA0-D9611BA75C81 <at> lepiller.eu>
and subject line OCaml CVE-2015-8869
has caused the debbugs.gnu.org bug report #27462,
regarding OCaml CVE-2015-8869 
to be marked as done.

(If you believe you have received this mail in error, please contact
help-debbugs <at> gnu.org.)


-- 
27462: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=27462
GNU Bug Tracking System
Contact help-debbugs <at> gnu.org with problems
[Message part 2 (message/rfc822, inline)]
From: Leo Famulari <leo <at> famulari.name>
To: bug-guix <at> gnu.org
Subject: OCaml CVE-2015-8869 
Date: Fri, 23 Jun 2017 12:41:29 -0400
[Message part 3 (text/plain, inline)]
Our package ocaml-4.01 is vulnerable to CVE-2015-8869, which we patched
in the primary ocaml package in April 2016. Unfortunately, this patch
was not included when the ocaml-4.01 package was created in January
2017.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8869

Do we need this older version of OCaml? If so, we need a volunteer to
maintain it.
[signature.asc (application/pgp-signature, inline)]
[Message part 5 (message/rfc822, inline)]
From: Julien Lepiller <julien <at> lepiller.eu>
To: 27462-done <at> debbugs.gnu.org
Subject: OCaml CVE-2015-8869
Date: Fri, 05 Jul 2019 14:12:56 +0200
Ocaml-4.02 was removed a few months ago in c3634df2 but I forgot to close this bug report.


This bug report was last modified 5 years and 326 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.