USN-3437-1: OCaml vulnerability
Publication date
3 October 2017
Overview
OCaml applications could be made to crash, expose sensitive information, or run programs.
Releases
Packages
- ocaml - ML language implementation with a class-based object system
Details
Radek Micek discovered that OCaml incorrectly handled sign extensions. A
remote attacker could use this issue to cause applications using OCaml to
crash, to possibly obtain sensitive information, or to possibly execute
arbitrary code.
Radek Micek discovered that OCaml incorrectly handled sign extensions. A
remote attacker could use this issue to cause applications using OCaml to
crash, to possibly obtain sensitive information, or to possibly execute
arbitrary code.
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
14.04 trusty | ocaml – 4.01.0-3ubuntu3.1 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.