Privilege Escalation in OCaml Compiler Versions 4.04.0 and 4.04.1 via Insufficient Sanitization

Privilege Escalation in OCaml Compiler Versions 4.04.0 and 4.04.1 via Insufficient Sanitization

CVE-2017-9772 · HIGH Severity

AV:N/AC:L/AU:N/C:C/I:C/A:C

Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variable.

Learn more about our External Network Penetration Testing.