CVE-2015-8869: Buffer Overflow

Published May 2, 2016
·
Updated

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.

Other sources

OCaml versions 4.02.3 and earlier have a runtime bug that, on 64-bit platforms, causes sizes arguments to an internal memmove call to be sign-extended from 32 to 64-bits before being passed to the memmove function.

This leads arguments between 2GiB and 4GiB to be interpreted as larger than they are (specifically, a bit below 2^64), causing a buffer overflow.

Arguments between 4GiB and 6GiB are interpreted as 4GiB smaller than they should be, causing a possible information leak.

References:

http://seclists.org/oss-sec/2016/q2/165

Upstream fix:

https://github.com/ocaml/ocaml/commit/659615c7b100a89eafe6253e7a5b9d84d0e8df74#diff-a97df53e3ebc59bb457191b496c90762

Red Hat

Affected Software

4 affected componentsFixes available
redhat/ocaml<4.03.0
4.03.0
Fedoraproject Fedora=24
openSUSE openSUSE=13.2
ocaml OCaml<=4.02.3

Event History

Jun 13, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2015-8869?

CVE-2015-8869 has been classified as a critical vulnerability due to its potential for remote exploitation and buffer overflow attacks.

2

How do I fix CVE-2015-8869?

To mitigate CVE-2015-8869, upgrade OCaml to version 4.03.0 or later.

3

Which versions of OCaml are affected by CVE-2015-8869?

OCaml versions 4.02.3 and earlier are affected by CVE-2015-8869.

4

What type of attack can CVE-2015-8869 facilitate?

CVE-2015-8869 can facilitate buffer overflow attacks which may lead to remote code execution or information disclosure.

5

On which platforms is CVE-2015-8869 a concern?

CVE-2015-8869 is particularly a concern on 64-bit platforms running affected OCaml versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203