Описание
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| ocaml | fixed | 5.2.0-1 | package | |
| ocaml | no-dsa | bookworm | package |
Примечания
https://github.com/ocaml/ocaml/issues/14655
Fixed as side effect in: https://github.com/ocaml/ocaml/pull/11022
Fixed by: https://github.com/ocaml/ocaml/commit/c667d0e1c5284f5ec46ee4a99b149fa5ac5dfe30 (5.0.0-alpha0)
Backport for 4.13.y series: https://github.com/ocaml/ocaml/pull/14691
EPSS
Связанные уязвимости
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.
EPSS