Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jg5-m986-f428

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.

EPSS

Процентиль: 86%
0.02814
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 9 лет назад

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.

redhat
больше 9 лет назад

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.

CVSS3: 9.1
nvd
около 9 лет назад

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.

CVSS3: 9.1
debian
около 9 лет назад

OCaml before 4.03.0 does not properly handle sign extensions, which al ...

suse-cvrf
почти 9 лет назад

Security update for ocaml

EPSS

Процентиль: 86%
0.02814
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-119