10

CVE-2017-9772

Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ocaml ≫ Ocaml Version 4.04.0
Ocaml ≫ Ocaml Version 4.04.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.5% 0.876
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/bid/99277
Third Party Advisory
VDB Entry
https://caml.inria.fr/mantis/view.php?id=7557
Third Party Advisory
Issue Tracking
https://security.gentoo.org/glsa/201710-07
https://sympa.inria.fr/sympa/arc/caml-list/2017-06/msg00094.html
Third Party Advisory
Issue Tracking