{"id":"UBUNTU-CVE-2017-9772","details":"Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variable.","modified":"2025-07-16T07:37:30.960822Z","published":"2017-06-23T20:29:00Z","withdrawn":"2025-07-18T16:44:01Z","upstream":["CVE-2017-9772"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-9772"},{"type":"REPORT","url":"https://sympa.inria.fr/sympa/arc/caml-list/2017-06/msg00094.html"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2017-9772"}],"affected":[{"package":{"name":"ocaml","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/ocaml@4.01.0-3ubuntu3?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.01.0-3ubuntu3"}]}],"versions":["3.12.1-4ubuntu1","4.01.0-3ubuntu2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"camlp4","binary_version":"4.01.0-3ubuntu3"},{"binary_name":"camlp4-extra","binary_version":"4.01.0-3ubuntu3"},{"binary_name":"ocaml","binary_version":"4.01.0-3ubuntu3"},{"binary_name":"ocaml-base","binary_version":"4.01.0-3ubuntu3"},{"binary_name":"ocaml-base-nox","binary_version":"4.01.0-3ubuntu3"},{"binary_name":"ocaml-compiler-libs","binary_version":"4.01.0-3ubuntu3"},{"binary_name":"ocaml-interp","binary_version":"4.01.0-3ubuntu3"},{"binary_name":"ocaml-mode","binary_version":"4.01.0-3ubuntu3"},{"binary_name":"ocaml-native-compilers","binary_version":"4.01.0-3ubuntu3"},{"binary_name":"ocaml-nox","binary_version":"4.01.0-3ubuntu3"},{"binary_name":"ocaml-source","binary_version":"4.01.0-3ubuntu3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-9772.json"}},{"package":{"name":"ocaml","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/ocaml@4.02.3-5ubuntu2?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.02.3-5ubuntu2"}]}],"versions":["4.01.0-4ubuntu1","4.02.3-5ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"ocaml","binary_version":"4.02.3-5ubuntu2"},{"binary_name":"ocaml-base","binary_version":"4.02.3-5ubuntu2"},{"binary_name":"ocaml-base-dbgsym","binary_version":"4.02.3-5ubuntu2"},{"binary_name":"ocaml-base-nox","binary_version":"4.02.3-5ubuntu2"},{"binary_name":"ocaml-base-nox-dbgsym","binary_version":"4.02.3-5ubuntu2"},{"binary_name":"ocaml-compiler-libs","binary_version":"4.02.3-5ubuntu2"},{"binary_name":"ocaml-interp","binary_version":"4.02.3-5ubuntu2"},{"binary_name":"ocaml-mode","binary_version":"4.02.3-5ubuntu2"},{"binary_name":"ocaml-native-compilers","binary_version":"4.02.3-5ubuntu2"},{"binary_name":"ocaml-native-compilers-dbgsym","binary_version":"4.02.3-5ubuntu2"},{"binary_name":"ocaml-nox","binary_version":"4.02.3-5ubuntu2"},{"binary_name":"ocaml-nox-dbgsym","binary_version":"4.02.3-5ubuntu2"},{"binary_name":"ocaml-source","binary_version":"4.02.3-5ubuntu2"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-9772.json"}},{"package":{"name":"ocaml","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/ocaml@4.05.0-10ubuntu1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.05.0-10ubuntu1"}]}],"versions":["4.04.0-2ubuntu4"],"ecosystem_specific":{"binaries":[{"binary_name":"ocaml","binary_version":"4.05.0-10ubuntu1"},{"binary_name":"ocaml-base","binary_version":"4.05.0-10ubuntu1"},{"binary_version":"4.05.0-10ubuntu1","binary_name":"ocaml-base-dbgsym"},{"binary_name":"ocaml-base-nox","binary_version":"4.05.0-10ubuntu1"},{"binary_name":"ocaml-base-nox-dbgsym","binary_version":"4.05.0-10ubuntu1"},{"binary_name":"ocaml-compiler-libs","binary_version":"4.05.0-10ubuntu1"},{"binary_name":"ocaml-interp","binary_version":"4.05.0-10ubuntu1"},{"binary_version":"4.05.0-10ubuntu1","binary_name":"ocaml-mode"},{"binary_name":"ocaml-nox","binary_version":"4.05.0-10ubuntu1"},{"binary_name":"ocaml-nox-dbgsym","binary_version":"4.05.0-10ubuntu1"},{"binary_name":"ocaml-source","binary_version":"4.05.0-10ubuntu1"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-9772.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}