Mageia 2019-0124: ocaml security update
Summary
The caml_ba_deserialize function in byterun/bigarray.c in the standard
library in OCaml 4.06.0 has an integer overflow which, in situations where
marshalled data is accepted from an untrusted source, allows remote
attackers to cause a denial of service (memory corruption) or possibly
execute arbitrary code via a crafted object. (CVE-2018-9838)
References
- https://bugs.mageia.org/show_bug.cgi?id=22948
- - https://bugzilla.suse.com/show_bug.cgi?id=1088591
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9838
Resolution
MGASA-2019-0124 - Updated ocaml packages fix security vulnerability
SRPMS
- 6/core/ocaml-4.02.3-6.1.mga6