Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-9838

Опубликовано: 06 апр. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ocaml:ocaml:4.06.0:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03589
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

CVSS3: 5.6
redhat
почти 8 лет назад

The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

CVSS3: 9.8
debian
почти 8 лет назад

The caml_ba_deserialize function in byterun/bigarray.c in the standard ...

suse-cvrf
больше 7 лет назад

Security update for ocaml

suse-cvrf
почти 8 лет назад

Security update for ocaml

EPSS

Процентиль: 87%
0.03589
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-190