{"id":"CVE-2017-9772","details":"Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variable.","aliases":["OSEC-2017-01"],"modified":"2026-07-08T16:54:37.170700Z","published":"2017-06-23T20:29:00.207Z","related":["openSUSE-SU-2024:10587-1"],"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/99277"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201710-07"},{"type":"REPORT","url":"https://caml.inria.fr/mantis/view.php?id=7557"},{"type":"REPORT","url":"https://sympa.inria.fr/sympa/arc/caml-list/2017-06/msg00094.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ocaml/ocaml","events":[{"introduced":"5d0f1bf69829d8d276402e29d0944fe2fc8e81c7"},{"last_affected":"7de17eaeccfe555eb2629af7e1048b0e5d492f01"}],"database_specific":{"cpe":["cpe:2.3:a:ocaml:ocaml:4.04.0:*:*:*:*:*:*:*","cpe:2.3:a:ocaml:ocaml:4.04.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.04.0"},{"last_affected":"4.04.0"},{"introduced":"4.04.1"},{"last_affected":"4.04.1"}],"source":"CPE_STRING"}}],"versions":["4.04.0","4.04.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9772.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}