Critical severity9.8NVD Advisory· Published Jun 23, 2017· Updated May 13, 2026
CVE-2017-9772
CVE-2017-9772
Description
Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variable.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.securityfocus.com/bid/99277nvdThird Party AdvisoryVDB Entry
- caml.inria.fr/mantis/view.phpnvdIssue TrackingThird Party Advisory
- sympa.inria.fr/sympa/arc/caml-list/2017-06/msg00094.htmlnvdIssue TrackingThird Party Advisory
- security.gentoo.org/glsa/201710-07nvd
News mentions
0No linked articles in our index yet.