Vulnerability Description
The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ocaml | Ocaml | 4.06.0 |
Related Weaknesses (CWE)
References
- https://caml.inria.fr/mantis/view.php?id=7765Issue TrackingVendor Advisory
- https://security.gentoo.org/glsa/202007-48
- https://caml.inria.fr/mantis/view.php?id=7765Issue TrackingVendor Advisory
- https://security.gentoo.org/glsa/202007-48
FAQ
What is CVE-2018-9838?
CVE-2018-9838 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, ...
How severe is CVE-2018-9838?
CVE-2018-9838 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-9838?
Check the references section above for vendor advisories and patch information. Affected products include: Ocaml Ocaml.