GNU bug report logs - #27462
OCaml CVE-2015-8869

Previous Next

Package: guix;

Reported by: Leo Famulari <leo <at> famulari.name>

Date: Fri, 23 Jun 2017 16:42:02 UTC

Severity: normal

Tags: security

Done: Julien Lepiller <julien <at> lepiller.eu>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: help-debbugs <at> gnu.org (GNU bug Tracking System)
To: Leo Famulari <leo <at> famulari.name>
Subject: bug#27462: closed (OCaml CVE-2015-8869)
Date: Fri, 05 Jul 2019 12:13:02 +0000
[Message part 1 (text/plain, inline)]
Your bug report

#27462: OCaml CVE-2015-8869 

which was filed against the guix package, has been closed.

The explanation is attached below, along with your original report.
If you require more details, please reply to 27462 <at> debbugs.gnu.org.

-- 
27462: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=27462
GNU Bug Tracking System
Contact help-debbugs <at> gnu.org with problems
[Message part 2 (message/rfc822, inline)]
From: Julien Lepiller <julien <at> lepiller.eu>
To: 27462-done <at> debbugs.gnu.org
Subject: OCaml CVE-2015-8869
Date: Fri, 05 Jul 2019 14:12:56 +0200
Ocaml-4.02 was removed a few months ago in c3634df2 but I forgot to close this bug report.

[Message part 3 (message/rfc822, inline)]
From: Leo Famulari <leo <at> famulari.name>
To: bug-guix <at> gnu.org
Subject: OCaml CVE-2015-8869 
Date: Fri, 23 Jun 2017 12:41:29 -0400
[Message part 4 (text/plain, inline)]
Our package ocaml-4.01 is vulnerable to CVE-2015-8869, which we patched
in the primary ocaml package in April 2016. Unfortunately, this patch
was not included when the ocaml-4.01 package was created in January
2017.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8869

Do we need this older version of OCaml? If so, we need a volunteer to
maintain it.
[signature.asc (application/pgp-signature, inline)]

This bug report was last modified 5 years and 326 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.