bug#27462: OCaml CVE-2015-8869

2019-07-05 Thread Julien Lepiller
Ocaml-4.02 was removed a few months ago in c3634df2 but I forgot to close this bug report.

bug#27462: OCaml CVE-2015-8869

2019-02-20 Thread Andreas Enge
On Wed, Feb 20, 2019 at 09:39:20AM +0100, Julien Lepiller wrote: > At this point, we only need it for bap and dependencies. I've added > dependencies for the latest bap commit that work with the latest ocaml, but > they haven't released a new version yet. Can we wait a bit longer? > > Another

bug#27462: OCaml CVE-2015-8869

2019-02-20 Thread Julien Lepiller
Le 19 février 2019 23:17:52 GMT+01:00, Andreas Enge a écrit : >On Thu, Jan 31, 2019 at 06:30:27PM +0100, Julien Lepiller wrote: >> I still care about ocaml-4.02, but I could probably update it to >ocaml-4.04 without breaking dependents. > >Commits 2e125ece093ef842ca017ffb146cbc5fa33f2f75 and

bug#27462: OCaml CVE-2015-8869

2019-02-19 Thread Andreas Enge
On Thu, Jan 31, 2019 at 06:30:27PM +0100, Julien Lepiller wrote: > I still care about ocaml-4.02, but I could probably update it to ocaml-4.04 > without breaking dependents. Commits 2e125ece093ef842ca017ffb146cbc5fa33f2f75 and 4982c0c98deecea0d4f69f14ea28cab53b5f2123 remove ocaml@4.01, pplacer

bug#27462: OCaml CVE-2015-8869

2019-01-31 Thread Julien Lepiller
Le 31 janvier 2019 18:21:13 GMT+01:00, Andreas Enge a écrit : >On Thu, Jan 31, 2019 at 05:57:03PM +0100, Andreas Enge wrote: >> Are people using the software > >I suppose not, because one of its dependencies currently does not >build: > >... >phase `ocaml-findlib-environment' succeeded after 0.0

bug#27462: OCaml CVE-2015-8869

2019-01-31 Thread swedebugia
On 2019-01-31 17:57, Andreas Enge wrote: Hello, this bug has been open for quite a while, and the development of pplacer seems to be stalled, with the latest commit in May 2018, and no reaction whatsoever to Ben's bug report https://github.com/matsen/pplacer/issues/354 How should we

bug#27462: OCaml CVE-2015-8869

2019-01-31 Thread Andreas Enge
On Thu, Jan 31, 2019 at 05:57:03PM +0100, Andreas Enge wrote: > Are people using the software I suppose not, because one of its dependencies currently does not build: ... phase `ocaml-findlib-environment' succeeded after 0.0 seconds starting phase `configure' build directory:

bug#27462: OCaml CVE-2015-8869

2019-01-31 Thread Andreas Enge
Hello, this bug has been open for quite a while, and the development of pplacer seems to be stalled, with the latest commit in May 2018, and no reaction whatsoever to Ben's bug report https://github.com/matsen/pplacer/issues/354 How should we continue? Are people using the software, or should

bug#27462: OCaml CVE-2015-8869

2017-06-24 Thread Leo Famulari
On Sat, Jun 24, 2017 at 10:25:52AM +1000, Ben Woodcroft wrote: > On 24/06/17 02:41, Leo Famulari wrote: > > Our package ocaml-4.01 is vulnerable to CVE-2015-8869, which we patched > > in the primary ocaml package in April 2016. Unfortunately, this patch > > was not included when the ocaml-4.01

bug#27462: OCaml CVE-2015-8869

2017-06-23 Thread Ben Woodcroft
Hi Leo, On 24/06/17 02:41, Leo Famulari wrote: Our package ocaml-4.01 is vulnerable to CVE-2015-8869, which we patched in the primary ocaml package in April 2016. Unfortunately, this patch was not included when the ocaml-4.01 package was created in January 2017.

bug#27462: OCaml CVE-2015-8869

2017-06-23 Thread Leo Famulari
Our package ocaml-4.01 is vulnerable to CVE-2015-8869, which we patched in the primary ocaml package in April 2016. Unfortunately, this patch was not included when the ocaml-4.01 package was created in January 2017. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8869 Do we need this