{"id":"CVE-2018-9838","details":"The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.","aliases":["OSEC-2018-01"],"modified":"2026-07-08T18:16:52.670897Z","published":"2018-04-06T18:29:00.207Z","related":["SUSE-SU-2018:0983-1","SUSE-SU-2018:1075-1","SUSE-SU-2018:1493-1","SUSE-SU-2018:1494-1","openSUSE-SU-2024:10587-1"],"references":[{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202007-48"},{"type":"REPORT","url":"https://caml.inria.fr/mantis/view.php?id=7765"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ocaml/ocaml","events":[{"introduced":"0d68080b95016f747b7cb63dd36ccdd42d40016e"},{"last_affected":"0d68080b95016f747b7cb63dd36ccdd42d40016e"}],"database_specific":{"cpe":"cpe:2.3:a:ocaml:ocaml:4.06.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.06.0"},{"last_affected":"4.06.0"}],"source":"CPE_STRING"}}],"versions":["4.06.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-9838.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}