Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-9838

Опубликовано: 06 апр. 2018
Источник: debian
EPSS Низкий

Описание

The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ocamlfixed4.05.0-11package
ocamlno-dsastretchpackage
ocamlno-dsajessiepackage
ocamlno-dsawheezypackage

Примечания

  • https://caml.inria.fr/mantis/view.php?id=7765

  • https://github.com/ocaml/ocaml/pull/1718

  • https://github.com/ocaml/ocaml/commit/9664c7ee807c2dfa802f53cabd405ff58e219c47

  • Before 4.06.0+beta1 the code is present in otherlibs/bigarray/bigarray_stubs.c

EPSS

Процентиль: 87%
0.03589
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

CVSS3: 5.6
redhat
почти 8 лет назад

The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

CVSS3: 9.8
nvd
почти 8 лет назад

The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

suse-cvrf
больше 7 лет назад

Security update for ocaml

suse-cvrf
почти 8 лет назад

Security update for ocaml

EPSS

Процентиль: 87%
0.03589
Низкий