Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Emilliken

#15110de 53,633
17.8CVSS total
Vulnerabilidades · 2
Alta
1
Crítica
1
PT-2017-19182
7.8
2017-07-12
Inria · Ocaml Compiler · CVE-2017-9779
**Name of the Vulnerable Software and Affected Versions** OCaml compiler (affected versions not specified) **Description** The OCaml compiler has an issue that allows attackers to have an unspecified impact. The impact of this issue is described as much less significant than a similar issue. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2017-19176
10
2017-06-23
Inria · Ocaml Compiler · CVE-2017-9772
**Name of the Vulnerable Software and Affected Versions** OCaml compiler versions 4.04.0 through 4.04.1 **Description** The issue is related to insufficient sanitisation in the OCaml compiler, which allows external code to be executed with raised privilege in binaries marked as setuid. This can be achieved by setting the `CAML CPLUGINS`, `CAML NATIVE CPLUGINS`, or `CAML BYTE CPLUGINS` environment variable. **Recommendations** For OCaml compiler version 4.04.0, update to a version that includes the necessary security fixes. For OCaml compiler version 4.04.1, update to a version that includes the necessary security fixes. As a temporary workaround, consider restricting the setting of the `CAML CPLUGINS`, `CAML NATIVE CPLUGINS`, and `CAML BYTE CPLUGINS` environment variables to minimize the risk of exploitation.