Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-9838

Опубликовано: 06 апр. 2018
Источник: ubuntu
Приоритет: low
CVSS2: 7.5
CVSS3: 9.8

Описание

The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

not-affected

4.05.0-11ubuntu1
disco

ignored

end of life
eoan

not-affected

4.05.0-11ubuntu1
esm-apps/bionic

released

4.05.0-10ubuntu1+esm1
esm-apps/focal

not-affected

4.05.0-11ubuntu1
esm-apps/jammy

not-affected

4.05.0-11ubuntu1
esm-apps/xenial

released

4.02.3-5ubuntu2+esm1

Показывать по

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 5.6
redhat
почти 8 лет назад

The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

CVSS3: 9.8
nvd
почти 8 лет назад

The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

CVSS3: 9.8
debian
почти 8 лет назад

The caml_ba_deserialize function in byterun/bigarray.c in the standard ...

suse-cvrf
больше 7 лет назад

Security update for ocaml

suse-cvrf
почти 8 лет назад

Security update for ocaml

7.5 High

CVSS2

9.8 Critical

CVSS3