CVE-2017-9772
Last modified
CVE-2017-9772 is a vulnerability of currently unknown severity. Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variable.. EPSS estimates a 3.50% chance of exploitation in the next 30 days.
Description
Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variable.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ocaml | Ocaml | 4.04.0 |
| Ocaml | Ocaml | 4.04.1 |
References
- http://www.securityfocus.com/bid/99277Third Party Advisory, VDB Entry
- https://caml.inria.fr/mantis/view.php?id=7557Issue Tracking, Third Party Advisory
- https://sympa.inria.fr/sympa/arc/caml-list/2017-06/msg00094.htmlIssue Tracking, Third Party Advisory
- http://www.securityfocus.com/bid/99277Third Party Advisory, VDB Entry
- https://caml.inria.fr/mantis/view.php?id=7557Issue Tracking, Third Party Advisory
- https://sympa.inria.fr/sympa/arc/caml-list/2017-06/msg00094.htmlIssue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-9772?
How severe is CVE-2017-9772?
How do I fix CVE-2017-9772?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-9765Integer overflow in the soap_get function in Genivia gSOAP 2…
- CVE-2017-9766In Wireshark 2.2.7, PROFINET IO data with a high recursion d…
- CVE-2017-9767Multiple cross-site scripting (XSS) vulnerabilities in Quali…
- CVE-2017-9769A specially crafted IOCTL can be issued to the rzpnk.sys dri…9.8
- CVE-2017-9770A specially crafted IOCTL can be issued to the rzpnk.sys dri…
- CVE-2017-9771install\save.php in WebsiteBaker v2.10.0 allows remote attac…
- CVE-2017-9773Denial of Service was found in Horde_Image 2.x before 2.5.0 …
- CVE-2017-9774Remote Code Execution was found in Horde_Image 2.x before 2.…
- CVE-2017-9775Stack buffer overflow in GfxState.cc in pdftocairo in Popple…
- CVE-2017-9776Integer overflow leading to Heap buffer overflow in JBIG2Str…
- CVE-2017-9778GNU Debugger (GDB) 8.0 and earlier fails to detect a negativ…
- CVE-2017-9779OCaml compiler allows attackers to have unspecified impact v…
Are you affected by CVE-2017-9772?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
