(address . bug-guix@gnu.org)
Our packages of OCaml 4.02.3 and 4.01.0 are vulnerable to CVE-2017-9772:
-----BEGIN PGP SIGNATURE-----
iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAllNRM4ACgkQJkb6MLrK
fwjhIRAAsdaeVYrsb5UAgjHljirS/54G3lbCC8faD+apw3ZoxsVWFvBcHBYwxMZg
4IbwDh/jIqskd82j5ITMB7tYFrG9VJd9GFUcT7Wy5dG5IUC0/dnRmqlH+Lj6a29H
hW1TN8MjDPNwjoAgTr6cj8FTr7jGNe4W6Lxkj3uUsegR8YREMf4jwN7h0occ298L
htob0j/NXx6OajbjRE2dyav8/jSyZI+gX9RAAqSXnsUhnRLx0ey78dVyDUAWtfSC
jaTmTq6C/GQJY8QX/DJrHTgDoOZvtKmTdygZmrdxu5EXh64R0PmO2yMzax4cojhP
pL6f1CYB/799j8GCFMBhc6J/J2h1WX2m2JFf7U1OgrdFSda2b1/Ouv0szhFWJZPd
6zlH3BKbVSLxtCY1/DUZXnWMxzTcauQvVb7VHnCeTOd3nP+I2dpkGvUnLFi7BPv8
Vg+/bI8QAh0yvpPUn75gTGxftSIXOGJgVbBySHOy4AjItzRVL3nAom3kI8xImf7X
zkHF2RFwQeXlI6BKtkOqL6u3tR0VU0785HI7oApNFe68gzb86X5YrFmraKi/vcPf
EEB/XlWnHbZrVXnuT3uXgz3HZupXO4lo9+0T/lmM1E3yQqcqLvRFDUXsrGJBwSYB
IAGvEXzfpTIlMB+pXJzqZ4Vuhq0cIJ83opaqkRx01GMZvfk8OmI=
=UZ/E
-----END PGP SIGNATURE-----