CVE-2015-8869

Description

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.

Risk Information

Base Score
9.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS Score
Exploitation Probability
3.774

Associated Vulnerability

VulnerabilityOS Platform
ML language implementation with a class-based object system (USN-3437-1) ocaml_4.01.0-3ubuntu3.1_i386.debLinux
ML language implementation with a class-based object system (USN-3437-1) ocaml_4.01.0-3ubuntu3.1_amd64.debLinux
Ocaml security update (CESA-2016:1296) ocaml-labltk-4.01.0-22.7.el7_2.x86_64.rpmLinux
Ocaml security update (CESA-2016:1296) ocaml-labltk-devel-4.01.0-22.7.el7_2.x86_64.rpmLinux
(RHSA-2016:1296) Moderate: ocaml security update ocaml-4.01.0-22.7.el7_2.x86_64.rpmLinux
(RHSA-2016:1296) Moderate: ocaml security update ocaml-camlp4-4.01.0-22.7.el7_2.x86_64.rpmLinux
(RHSA-2016:1296) Moderate: ocaml security update ocaml-camlp4-devel-4.01.0-22.7.el7_2.x86_64.rpmLinux
(RHSA-2016:1296) Moderate: ocaml security update ocaml-compiler-libs-4.01.0-22.7.el7_2.x86_64.rpmLinux
(RHSA-2016:1296) Moderate: ocaml security update ocaml-docs-4.01.0-22.7.el7_2.x86_64.rpmLinux
(RHSA-2016:1296) Moderate: ocaml security update ocaml-emacs-4.01.0-22.7.el7_2.x86_64.rpmLinux
(RHSA-2016:1296) Moderate: ocaml security update ocaml-labltk-4.01.0-22.7.el7_2.x86_64.rpmLinux
(RHSA-2016:1296) Moderate: ocaml security update ocaml-labltk-devel-4.01.0-22.7.el7_2.x86_64.rpmLinux
(RHSA-2016:1296) Moderate: ocaml security update ocaml-ocamldoc-4.01.0-22.7.el7_2.x86_64.rpmLinux
(RHSA-2016:1296) Moderate: ocaml security update ocaml-runtime-4.01.0-22.7.el7_2.x86_64.rpmLinux
(RHSA-2016:1296) Moderate: ocaml security update ocaml-source-4.01.0-22.7.el7_2.x86_64.rpmLinux
(RHSA-2016:1296) Moderate: ocaml security update ocaml-x11-4.01.0-22.7.el7_2.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-bash-completion-1.32.7-3.el7.noarch.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-devel-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-gfs2-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-gobject-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-gobject-devel-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-gobject-doc-1.32.7-3.el7.noarch.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-inspect-icons-1.32.7-3.el7.noarch.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-java-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-java-devel-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-javadoc-1.32.7-3.el7.noarch.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-man-pages-ja-1.32.7-3.el7.noarch.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-man-pages-uk-1.32.7-3.el7.noarch.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-rescue-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-rsync-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-tools-1.32.7-3.el7.noarch.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-tools-c-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update libguestfs-xfs-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update lua-guestfs-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update ocaml-libguestfs-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update ocaml-libguestfs-devel-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update perl-Sys-Guestfs-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update python-libguestfs-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update ruby-libguestfs-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update virt-dib-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update virt-p2v-1.32.7-2.el7.noarch.rpmLinux
(RHSA-2016:2576) Moderate: libguestfs and virt-p2v security, bug fix, and enhancement update virt-v2v-1.32.7-3.el7.x86_64.rpmLinux
(RHSA-2017:0564) Moderate: libguestfs security and bug fix update libguestfs-1.20.11-20.el6.x86_64.rpmLinux
(RHSA-2017:0564) Moderate: libguestfs security and bug fix update libguestfs-devel-1.20.11-20.el6.x86_64.rpmLinux
(RHSA-2017:0564) Moderate: libguestfs security and bug fix update libguestfs-java-1.20.11-20.el6.x86_64.rpmLinux
(RHSA-2017:0564) Moderate: libguestfs security and bug fix update libguestfs-java-devel-1.20.11-20.el6.x86_64.rpmLinux
(RHSA-2017:0564) Moderate: libguestfs security and bug fix update libguestfs-javadoc-1.20.11-20.el6.x86_64.rpmLinux
(RHSA-2017:0564) Moderate: libguestfs security and bug fix update libguestfs-tools-1.20.11-20.el6.x86_64.rpmLinux
(RHSA-2017:0564) Moderate: libguestfs security and bug fix update libguestfs-tools-c-1.20.11-20.el6.x86_64.rpmLinux
(RHSA-2017:0564) Moderate: libguestfs security and bug fix update ocaml-libguestfs-1.20.11-20.el6.x86_64.rpmLinux
(RHSA-2017:0564) Moderate: libguestfs security and bug fix update ocaml-libguestfs-devel-1.20.11-20.el6.x86_64.rpmLinux
(RHSA-2017:0564) Moderate: libguestfs security and bug fix update perl-Sys-Guestfs-1.20.11-20.el6.x86_64.rpmLinux
(RHSA-2017:0564) Moderate: libguestfs security and bug fix update python-libguestfs-1.20.11-20.el6.x86_64.rpmLinux
(RHSA-2017:0564) Moderate: libguestfs security and bug fix update ruby-libguestfs-1.20.11-20.el6.x86_64.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-3.11.2-5.el6.i686.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-3.11.2-5.el6.x86_64.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-camlp4-3.11.2-5.el6.i686.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-camlp4-3.11.2-5.el6.x86_64.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-camlp4-devel-3.11.2-5.el6.i686.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-camlp4-devel-3.11.2-5.el6.x86_64.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-docs-3.11.2-5.el6.i686.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-docs-3.11.2-5.el6.x86_64.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-emacs-3.11.2-5.el6.i686.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-emacs-3.11.2-5.el6.x86_64.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-labltk-3.11.2-5.el6.i686.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-labltk-3.11.2-5.el6.x86_64.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-labltk-devel-3.11.2-5.el6.i686.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-labltk-devel-3.11.2-5.el6.x86_64.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-ocamldoc-3.11.2-5.el6.i686.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-ocamldoc-3.11.2-5.el6.x86_64.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-runtime-3.11.2-5.el6.i686.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-runtime-3.11.2-5.el6.x86_64.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-source-3.11.2-5.el6.i686.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-source-3.11.2-5.el6.x86_64.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-x11-3.11.2-5.el6.i686.rpmLinux
(RHSA-2017:0565) Moderate: ocaml security update ocaml-x11-3.11.2-5.el6.x86_64.rpmLinux
Libguestfs update (ELSA-2017-0564) libguestfs-1.20.11-20.el6.x86_64.rpmLinux
Libguestfs-devel update (ELSA-2017-0564) libguestfs-devel-1.20.11-20.el6.x86_64.rpmLinux
Libguestfs-java update (ELSA-2017-0564) libguestfs-java-1.20.11-20.el6.x86_64.rpmLinux
Libguestfs-java-devel update (ELSA-2017-0564) libguestfs-java-devel-1.20.11-20.el6.x86_64.rpmLinux
Libguestfs-javadoc update (ELSA-2017-0564) libguestfs-javadoc-1.20.11-20.el6.x86_64.rpmLinux
Libguestfs-tools update (ELSA-2017-0564) libguestfs-tools-1.20.11-20.el6.x86_64.rpmLinux
Libguestfs-tools-c update (ELSA-2017-0564) libguestfs-tools-c-1.20.11-20.el6.x86_64.rpmLinux
Ocaml-libguestfs update (ELSA-2017-0564) ocaml-libguestfs-1.20.11-20.el6.x86_64.rpmLinux
Ocaml-libguestfs-devel update (ELSA-2017-0564) ocaml-libguestfs-devel-1.20.11-20.el6.x86_64.rpmLinux
Perl-Sys-Guestfs update (ELSA-2017-0564) perl-Sys-Guestfs-1.20.11-20.el6.x86_64.rpmLinux
Python-libguestfs update (ELSA-2017-0564) python-libguestfs-1.20.11-20.el6.x86_64.rpmLinux
Ruby-libguestfs update (ELSA-2017-0564) ruby-libguestfs-1.20.11-20.el6.x86_64.rpmLinux
(CESA-2017:0564) Moderate: libguestfs security and bug fix update libguestfs-1.20.11-20.el6.x86_64.rpmLinux
(CESA-2017:0564) Moderate: libguestfs security and bug fix update libguestfs-devel-1.20.11-20.el6.x86_64.rpmLinux
(CESA-2017:0564) Moderate: libguestfs security and bug fix update libguestfs-java-1.20.11-20.el6.x86_64.rpmLinux
(CESA-2017:0564) Moderate: libguestfs security and bug fix update libguestfs-java-devel-1.20.11-20.el6.x86_64.rpmLinux
(CESA-2017:0564) Moderate: libguestfs security and bug fix update libguestfs-javadoc-1.20.11-20.el6.x86_64.rpmLinux
(CESA-2017:0564) Moderate: libguestfs security and bug fix update libguestfs-tools-1.20.11-20.el6.x86_64.rpmLinux
(CESA-2017:0564) Moderate: libguestfs security and bug fix update libguestfs-tools-c-1.20.11-20.el6.x86_64.rpmLinux
(CESA-2017:0564) Moderate: libguestfs security and bug fix update ocaml-libguestfs-1.20.11-20.el6.x86_64.rpmLinux
(CESA-2017:0564) Moderate: libguestfs security and bug fix update ocaml-libguestfs-devel-1.20.11-20.el6.x86_64.rpmLinux
(CESA-2017:0564) Moderate: libguestfs security and bug fix update perl-Sys-Guestfs-1.20.11-20.el6.x86_64.rpmLinux
(CESA-2017:0564) Moderate: libguestfs security and bug fix update python-libguestfs-1.20.11-20.el6.x86_64.rpmLinux
(CESA-2017:0564) Moderate: libguestfs security and bug fix update ruby-libguestfs-1.20.11-20.el6.x86_64.rpmLinux
(CESA-2017:0565) Moderate: ocaml security update ocaml-3.11.2-5.el6.i686.rpmLinux
(CESA-2017:0565) Moderate: ocaml security update ocaml-camlp4-3.11.2-5.el6.i686.rpmLinux
(CESA-2017:0565) Moderate: ocaml security update ocaml-camlp4-devel-3.11.2-5.el6.i686.rpmLinux
(CESA-2017:0565) Moderate: ocaml security update ocaml-docs-3.11.2-5.el6.i686.rpmLinux
(CESA-2017:0565) Moderate: ocaml security update ocaml-emacs-3.11.2-5.el6.i686.rpmLinux
(CESA-2017:0565) Moderate: ocaml security update ocaml-labltk-3.11.2-5.el6.i686.rpmLinux
(CESA-2017:0565) Moderate: ocaml security update ocaml-labltk-devel-3.11.2-5.el6.i686.rpmLinux
(CESA-2017:0565) Moderate: ocaml security update ocaml-ocamldoc-3.11.2-5.el6.i686.rpmLinux
(CESA-2017:0565) Moderate: ocaml security update ocaml-runtime-3.11.2-5.el6.i686.rpmLinux
(CESA-2017:0565) Moderate: ocaml security update ocaml-source-3.11.2-5.el6.i686.rpmLinux
(CESA-2017:0565) Moderate: ocaml security update ocaml-x11-3.11.2-5.el6.i686.rpmLinux
(RHSA-2016:1296)Moderate: security update ocaml-debuginfo-4.01.0-22.7.el7_2.x86_64.rpmLinux
(RHSA-2016:2576)Moderate: and virt-p2v security, bug fix, and enhancement update libguestfs-debuginfo-1.32.7-3.el7.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234