Candidate: CVE-2017-9772 PublicDate: 2017-06-23 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9772 https://sympa.inria.fr/sympa/arc/caml-list/2017-06/msg00094.html Description: Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variable. Ubuntu-Description: Notes: seth-arnold> Look for further modifications that would handle filesystem capabilities or other reasons for `AT_SECURE` to be set in getauxval(3). mdeslaur> only affects 4.04.0 and 4.04.1 Bugs: https://caml.inria.fr/mantis/view.php?id=7557 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_ocaml: upstream: https://github.com/ocaml/ocaml/commit/38e2cd6a580e5b14a503f34d5ca7709d190c36a3 upstream: https://github.com/ocaml/ocaml/commit/bd801361f855017a2fb13435e218bc7fbbaf0896 upstream: https://github.com/ocaml/ocaml/commit/850021c200c7507f2a928a66fa1291ff4ae3a622 upstream_ocaml: released (4.04.2) precise/esm_ocaml: DNE trusty_ocaml: not-affected (4.01.0-3ubuntu3) trusty/esm_ocaml: not-affected (4.01.0-3ubuntu3) vivid/ubuntu-core_ocaml: DNE xenial_ocaml: not-affected (4.02.3-5ubuntu2) yakkety_ocaml: ignored (reached end-of-life) zesty_ocaml: not-affected (4.02.3-6ubuntu2) artful_ocaml: ignored (reached end-of-life) bionic_ocaml: not-affected (4.05.0-10ubuntu1) cosmic_ocaml: not-affected (4.05.0-10ubuntu1) disco_ocaml: not-affected (4.05.0-10ubuntu1) devel_ocaml: not-affected (4.05.0-10ubuntu1)