CVE-2015-8869
published 2016-06-13CVE-2015-8869: OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information…
PriorityP346critical9.1CVSS 3.0
AVNACLPRNUINSUCHINAH
EPSS
5.27%
91.6th percentile
OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ocaml | < ocaml 4.02.3-9 (bookworm) | ocaml 4.02.3-9 (bookworm) |
| fedoraproject | fedora | — | — |
| ocaml | ocaml | <= 4.02.3 | — |
| ocaml | ocaml | >= 0 < 4.02.3-9 | 4.02.3-9 |
| ocaml | ocaml | >= 0 < 4.02.3-9 | 4.02.3-9 |
| ocaml | ocaml | >= 0 < 4.02.3-9 | 4.02.3-9 |
| ocaml | ocaml | >= 0 < 4.02.3-9 | 4.02.3-9 |
| ocaml | ocaml | >= 0 < 4.01.0-3ubuntu3.1+esm1 | 4.01.0-3ubuntu3.1+esm1 |
| ocaml | ocaml | >= 0 < 4.02.3-5ubuntu2+esm1 | 4.02.3-5ubuntu2+esm1 |
| ocaml | ocaml | >= 0 < 4.05.0-10ubuntu1+esm1 | 4.05.0-10ubuntu1+esm1 |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OCaml vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 9.1
CVE-2015-8869 [CRITICAL] OCaml vulnerabilities
Title: OCaml vulnerabilities
Summary: Several security issues were fixed in ocaml.
It was discovered that OCaml mishandled sign extensions. A remote attacker
could use this vulnerability to steal sensitive information, cause a denial
of service (crash), or possibly execute arbitrary code. This issue only
affected Ubuntu 16.04 ESM. (CVE-2015-8869)
It was discovered that OCaml mishandled crafted input. An attacker could
use this vulnerability to cause a denial of service or possibly execute
arbitrary code. (CVE-2018-9838)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
OCaml vulnerability
vendor_ubuntu·2017-10-03
CVE-2015-8869 OCaml vulnerability
Title: OCaml vulnerability
Summary: OCaml applications could be made to crash, expose sensitive information, or
run programs.
Radek Micek discovered that OCaml incorrectly handled sign extensions. A
remote attacker could use this issue to cause applications using OCaml to
crash, to possibly obtain sensitive information, or to possibly execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ocaml: sizes arguments are sign-extended from 32 to 64 bits
vendor_redhat·2016-04-28·CVSS 9.1
CVE-2015-8869 [CRITICAL] CWE-194 ocaml: sizes arguments are sign-extended from 32 to 64 bits
ocaml: sizes arguments are sign-extended from 32 to 64 bits
OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.
An integer conversion flaw was found in the way OCaml's String handled its length. Certain operations on an excessively long String could trigger a buffer overflow or result in an information leak.
Debian
CVE-2015-8869: ocaml - OCaml before 4.03.0 does not properly handle sign extensions, which allows remot...
vendor_debian·2015·CVSS 9.1
CVE-2015-8869 [CRITICAL] CVE-2015-8869: ocaml - OCaml before 4.03.0 does not properly handle sign extensions, which allows remot...
OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.
Scope: local
bookworm: resolved (fixed in 4.02.3-9)
bullseye: resolved (fixed in 4.02.3-9)
forky: resolved (fixed in 4.02.3-9)
sid: resolved (fixed in 4.02.3-9)
trixie: resolved (fixed in 4.02.3-9)
GHSA
GHSA-3jg5-m986-f428: OCaml before 4
ghsa_unreviewed·2022-05-14
CVE-2015-8869 [CRITICAL] CWE-119 GHSA-3jg5-m986-f428: OCaml before 4
OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.
OSV
ocaml vulnerabilities
osv·2021-03-15·CVSS 9.1
CVE-2015-8869 [CRITICAL] ocaml vulnerabilities
ocaml vulnerabilities
It was discovered that OCaml mishandled sign extensions. A remote attacker
could use this vulnerability to steal sensitive information, cause a denial
of service (crash), or possibly execute arbitrary code. This issue only
affected Ubuntu 16.04 ESM. (CVE-2015-8869)
It was discovered that OCaml mishandled crafted input. An attacker could
use this vulnerability to cause a denial of service or possibly execute
arbitrary code. (CVE-2018-9838)
OSV
CVE-2015-8869: OCaml before 4
osv·2016-06-13·CVSS 9.1
CVE-2015-8869 [CRITICAL] CVE-2015-8869: OCaml before 4
OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8869 ocaml: sizes arguments are sign-extended from 32 to 64 bits [fedora-all]
bugzilla·2016-05-02·CVSS 9.1
CVE-2015-8869 [CRITICAL] CVE-2015-8869 ocaml: sizes arguments are sign-extended from 32 to 64 bits [fedora-all]
CVE-2015-8869 ocaml: sizes arguments are sign-extended from 32 to 64 bits [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2015-8869 ocaml: sizes arguments are sign-extended from 32 to 64 bits
bugzilla·2016-05-02·CVSS 9.1
CVE-2015-8869 [CRITICAL] CVE-2015-8869 ocaml: sizes arguments are sign-extended from 32 to 64 bits
CVE-2015-8869 ocaml: sizes arguments are sign-extended from 32 to 64 bits
OCaml versions 4.02.3 and earlier have a runtime bug that, on 64-bit platforms, causes sizes arguments to an internal memmove call to be sign-extended from 32 to 64-bits before being passed to the memmove function.
This leads arguments between 2GiB and 4GiB to be interpreted as larger than they are (specifically, a bit below 2^64), causing a buffer overflow.
Arguments between 4GiB and 6GiB are interpreted as 4GiB smaller than they should be, causing a possible information leak.
References:
http://seclists.org/oss-sec/2016/q2/165
Upstream fix:
https://github.com/ocaml/ocaml/commit/659615c7b100a89eafe6253e7a5b9d84d0e8df74#diff-a97df53e3ebc59bb457191b496c90762
Discussion:
Created ocaml tracking bugs for this is
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184507.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00081.htmlhttp://lists.opensuse.org/opensuse-updates/2016-09/msg00037.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2576.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0564.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0565.htmlhttp://www.openwall.com/lists/oss-security/2016/04/29/1http://www.openwall.com/lists/oss-security/2016/04/29/6http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.securityfocus.com/bid/89318https://access.redhat.com/errata/RHSA-2016:1296https://github.com/ocaml/ocaml/commit/659615c7b100a89eafe6253e7a5b9d84d0e8df74#diff-a97df53e3ebc59bb457191b496c90762https://security.gentoo.org/glsa/201702-15http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184507.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00081.htmlhttp://lists.opensuse.org/opensuse-updates/2016-09/msg00037.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2576.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0564.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0565.htmlhttp://www.openwall.com/lists/oss-security/2016/04/29/1http://www.openwall.com/lists/oss-security/2016/04/29/6http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.securityfocus.com/bid/89318https://access.redhat.com/errata/RHSA-2016:1296https://github.com/ocaml/ocaml/commit/659615c7b100a89eafe6253e7a5b9d84d0e8df74#diff-a97df53e3ebc59bb457191b496c90762https://security.gentoo.org/glsa/201702-15
2016-06-13
Published