Oval Definition:oval:com.redhat.rhsa:def:20161296
Revision Date:2016-06-23Version:640
Title:RHSA-2016:1296: ocaml security update (Moderate)
Description:OCaml is a high-level, strongly-typed, functional, and object-oriented programming language from the ML family of languages. The ocaml packages contain two batch compilers (a fast bytecode compiler and an optimizing native-code compiler), an interactive top level system, parsing tools (Lex, Yacc, Camlp4), a replay debugger, a documentation generator, and a comprehensive library.

Security Fix(es):

  • OCaml versions 4.02.3 and earlier have a runtime bug that, on 64-bit platforms, causes size arguments to internal memmove calls to be sign-extended from 32- to 64-bits before being passed to the memmove function. This leads to arguments between 2GiB and 4GiB being interpreted as larger than they are (specifically, a bit below 2^64), causing a buffer overflow. Further, arguments between 4GiB and 6GiB are interpreted as 4GiB smaller than they should be, causing a possible information leak. (CVE-2015-8869)
  • Family:unixClass:patch
    Status:Reference(s):CVE-2015-8869
    RHSA-2016:1296
    RHSA-2016:1296-00
    RHSA-2016:1296-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • ocaml is earlier than 0:4.01.0-22.7.el7_2
  • AND ocaml is signed with Red Hat redhatrelease2 key
  • ocaml-camlp4 is earlier than 0:4.01.0-22.7.el7_2
  • AND ocaml-camlp4 is signed with Red Hat redhatrelease2 key
  • ocaml-camlp4-devel is earlier than 0:4.01.0-22.7.el7_2
  • AND ocaml-camlp4-devel is signed with Red Hat redhatrelease2 key
  • ocaml-compiler-libs is earlier than 0:4.01.0-22.7.el7_2
  • AND ocaml-compiler-libs is signed with Red Hat redhatrelease2 key
  • ocaml-docs is earlier than 0:4.01.0-22.7.el7_2
  • AND ocaml-docs is signed with Red Hat redhatrelease2 key
  • ocaml-emacs is earlier than 0:4.01.0-22.7.el7_2
  • AND ocaml-emacs is signed with Red Hat redhatrelease2 key
  • ocaml-labltk is earlier than 0:4.01.0-22.7.el7_2
  • AND ocaml-labltk is signed with Red Hat redhatrelease2 key
  • ocaml-labltk-devel is earlier than 0:4.01.0-22.7.el7_2
  • AND ocaml-labltk-devel is signed with Red Hat redhatrelease2 key
  • ocaml-ocamldoc is earlier than 0:4.01.0-22.7.el7_2
  • AND ocaml-ocamldoc is signed with Red Hat redhatrelease2 key
  • ocaml-runtime is earlier than 0:4.01.0-22.7.el7_2
  • AND ocaml-runtime is signed with Red Hat redhatrelease2 key
  • ocaml-source is earlier than 0:4.01.0-22.7.el7_2
  • AND ocaml-source is signed with Red Hat redhatrelease2 key
  • ocaml-x11 is earlier than 0:4.01.0-22.7.el7_2
  • AND ocaml-x11 is signed with Red Hat redhatrelease2 key
  • BACK