From mboxrd@z Thu Jan 1 00:00:00 1970 From: Julien Lepiller Subject: bug#27462: OCaml CVE-2015-8869 Date: Wed, 20 Feb 2019 09:39:20 +0100 Message-ID: <5510C5B2-07EA-4D26-9629-1403237F6751@lepiller.eu> References: <20190131165613.GA27597@jurong> <20190131172113.GA29071@jurong> <96513178-922C-49D6-AF32-0EF723343C8E@lepiller.eu> <20190219221752.GA4351@jurong> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([209.51.188.92]:52146) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gwNQB-0004HT-Oq for bug-guix@gnu.org; Wed, 20 Feb 2019 03:40:04 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gwNQA-0000iX-Ut for bug-guix@gnu.org; Wed, 20 Feb 2019 03:40:03 -0500 Received: from debbugs.gnu.org ([209.51.188.43]:56403) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1gwNQA-0000hx-Px for bug-guix@gnu.org; Wed, 20 Feb 2019 03:40:02 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1gwNQA-0007Ck-KU for bug-guix@gnu.org; Wed, 20 Feb 2019 03:40:02 -0500 Sender: "Debbugs-submit" Resent-Message-ID: In-Reply-To: <20190219221752.GA4351@jurong> List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: Andreas Enge Cc: 27462@debbugs.gnu.org Le 19 f=C3=A9vrier 2019 23:17:52 GMT+01:00, Andreas Enge a =C3=A9crit : >On Thu, Jan 31, 2019 at 06:30:27PM +0100, Julien Lepiller wrote: >> I still care about ocaml-4=2E02, but I could probably update it to >ocaml-4=2E04 without breaking dependents=2E > >Commits 2e125ece093ef842ca017ffb146cbc5fa33f2f75 and >4982c0c98deecea0d4f69f14ea28cab53b5f2123 remove ocaml@4=2E01, pplacer and >all other dependent packages=2E > >Is ocaml@4=2E02 really needed? It would be nice to get rid of a package >with CVE=2E > >Andreas At this point, we only need it for bap and dependencies=2E I've added depe= ndencies for the latest bap commit that work with the latest ocaml, but the= y haven't released a new version yet=2E Can we wait a bit longer? Another solution would be to jump to ocaml 4=2E05 and re-package another v= ersion of ~50 dependencies=2E I don't really want to do that=E2=80=A6