CVE-2017-9772: Critical severity suse ocaml runtime vulnerability
Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAMLCPLUGINS, CAMLNATIVECPLUGINS, or CAMLBYTECPLUGINS environment variable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9772?
CVE-2017-9772 has a high severity due to its potential for executing external code with elevated privileges in setuid binaries.
How do I fix CVE-2017-9772?
To fix CVE-2017-9772, upgrade to OCaml version 4.04.2 or later, which addresses the insufficient sanitization issue.
Which versions of OCaml are affected by CVE-2017-9772?
CVE-2017-9772 affects OCaml versions 4.04.0 and 4.04.1.
What type of vulnerability is CVE-2017-9772?
CVE-2017-9772 is a code execution vulnerability caused by insufficient sanitization in the OCaml compiler.
What are the potential risks of CVE-2017-9772?
The risks of CVE-2017-9772 include unauthorized code execution and potential system compromise due to elevated privileges.