Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-9838

Опубликовано: 06 апр. 2018
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ocamlWill not fix
Red Hat Enterprise Linux 7ocamlFix deferred
Red Hat Enterprise Linux 8ocamlNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1565468ocaml: Integer overflow in byterun/bigarray.c:caml_ba_deserialize() allows remote attackers to cause a denial of service or other unspecified impact

EPSS

Процентиль: 88%
0.03589
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

CVSS3: 9.8
nvd
почти 8 лет назад

The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

CVSS3: 9.8
debian
почти 8 лет назад

The caml_ba_deserialize function in byterun/bigarray.c in the standard ...

suse-cvrf
больше 7 лет назад

Security update for ocaml

suse-cvrf
почти 8 лет назад

Security update for ocaml

EPSS

Процентиль: 88%
0.03589
Низкий

5.6 Medium

CVSS3