Integer Overflow Vulnerability in OCaml's caml_ba_deserialize Function

Integer Overflow Vulnerability in OCaml's caml_ba_deserialize Function

CVE-2018-9838 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

Learn more about our Web Application Penetration Testing UK.