The caml_ba_deserialize function in byterun/bigarray.c in the standard
library in OCaml 4.06.0 has an integer overflow which, in situations where
marshalled data is accepted from an untrusted source, allows remote
attackers to cause a denial of service (memory corruption) or possibly
execute arbitrary code via a crafted object. (CVE-2018-9838)
- https://bugs.mageia.org/show_bug.cgi?id=22948
- - https://bugzilla.suse.com/show_bug.cgi?id=1088591
- - https://www.cve.org/CVERecord?id=CVE-2018-9838
- 6/core/ocaml-4.02.3-6.1.mga6
Get the latest Linux and open source security news straight to your inbox.