Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 26 ocaml Privilege Escalation Advisory: Critical Update

fedora
Calendar Grey July 7, 2017
Dist Fedora Esm H88
Important patch for Ubuntu 20.04 tackling vulnerability in python3. Ensure you upgrade using apt to safeguard your system.
Fix: ocaml: Insufficient sanitisation allows privilege escalation for setuid binaries (CVE-2017-9772) (RHBZ#1464920).

Summary

OCaml is a high-level, strongly-typed, functional and object-oriented

programming language from the ML family of languages.

This package comprises two batch compilers (a fast bytecode compiler

and an optimizing native-code compiler), an interactive toplevel system,

parsing tools (Lex,Yacc), a replay debugger, a documentation generator,

and a comprehensive library.

Fix: ocaml: Insufficient sanitisation allows privilege escalation for setuid

binaries (CVE-2017-9772) (RHBZ#1464920).

[ 1 ] Bug #1464920 - CVE-2017-9772 ocaml: Insufficient sanitisation allows privilege escalation for setuid binaries

https://bugzilla.redhat.com/show_bug.cgi?id=1464920

su -c 'dnf upgrade ocaml' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 4.04.0
Release: 10.fc26
Summary: OCaml compiler and programming environment

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here