Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jg5-m986-f428

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.

EPSS

Процентиль: 92%
0.05267
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 10 лет назад

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.

redhat
больше 10 лет назад

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.

CVSS3: 9.1
nvd
около 10 лет назад

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.

CVSS3: 9.1
debian
около 10 лет назад

OCaml before 4.03.0 does not properly handle sign extensions, which al ...

suse-cvrf
почти 10 лет назад

Security update for ocaml

EPSS

Процентиль: 92%
0.05267
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-119