CVE-2017-9772
Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variable.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.50% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- ocaml/ocaml
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/99277Third Party Advisory, VDB Entry
- https://caml.inria.fr/mantis/view.php?id=7557Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/201710-07
- https://sympa.inria.fr/sympa/arc/caml-list/2017-06/msg00094.htmlIssue Tracking, Third Party Advisory
- http://www.securityfocus.com/bid/99277Third Party Advisory, VDB Entry
- https://caml.inria.fr/mantis/view.php?id=7557Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/201710-07
- https://sympa.inria.fr/sympa/arc/caml-list/2017-06/msg00094.htmlIssue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.