CVE-2017-9772
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/06/2017
Last modified:
20/04/2025
Description
Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variable.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ocaml:ocaml:4.04.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ocaml:ocaml:4.04.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.securityfocus.com/bid/99277
- https://caml.inria.fr/mantis/view.php?id=7557
- https://security.gentoo.org/glsa/201710-07
- https://sympa.inria.fr/sympa/arc/caml-list/2017-06/msg00094.html
- http://www.securityfocus.com/bid/99277
- https://caml.inria.fr/mantis/view.php?id=7557
- https://security.gentoo.org/glsa/201710-07
- https://sympa.inria.fr/sympa/arc/caml-list/2017-06/msg00094.html



