PT-2017-19176 · Inria+1 · Ocaml Compiler+1
Emilliken
·
Published
2017-06-23
·
Updated
2019-10-03
·
CVE-2017-9772
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OCaml compiler versions 4.04.0 through 4.04.1
Description
The issue is related to insufficient sanitisation in the OCaml compiler, which allows external code to be executed with raised privilege in binaries marked as setuid. This can be achieved by setting the
CAML CPLUGINS, CAML NATIVE CPLUGINS, or CAML BYTE CPLUGINS environment variable.Recommendations
For OCaml compiler version 4.04.0, update to a version that includes the necessary security fixes.
For OCaml compiler version 4.04.1, update to a version that includes the necessary security fixes.
As a temporary workaround, consider restricting the setting of the
CAML CPLUGINS, CAML NATIVE CPLUGINS, and CAML BYTE CPLUGINS environment variables to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Ocaml Compiler