CVE-2015-8869

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
Affected Products (NVD)
VendorProductVersion
opensuseopensuse
13.2
ocamlocaml
𝑥
≤ 4.02.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ocaml
bookworm
4.13.1-4
fixed
bullseye
4.11.1-4
fixed
jessie
no-dsa
sid
5.2.0-3
fixed
trixie
5.2.0-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ocaml
artful
ignored
bionic
not-affected
cosmic
not-affected
disco
not-affected
eoan
not-affected
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
precise
ignored
trusty
Fixed 4.01.0-3ubuntu3.1
released
wily
ignored
xenial
Fixed 4.02.3-5ubuntu2+esm1
released
yakkety
ignored
zesty
ignored
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
ocaml
suse enterprise desktop 15
4.05.0-4.25
fixed
suse enterprise desktop 15 SP1
4.05.0-4.25
fixed
suse enterprise desktop 15 SP2
4.05.0-13.5
fixed
suse enterprise desktop 15 SP3
4.05.0-13.5
fixed
suse enterprise desktop 15 SP4
4.05.0-13.5
fixed
suse enterprise desktop 15 SP5
4.05.0-13.5
fixed
suse enterprise desktop 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise desktop 15 SP7
4.14.2-150600.1.2
fixed
suse enterprise sap 15
4.05.0-4.25
fixed
suse enterprise sap 15 SP1
4.05.0-4.25
fixed
suse enterprise sap 15 SP2
4.05.0-13.5
fixed
suse enterprise sap 15 SP3
4.05.0-13.5
fixed
suse enterprise sap 15 SP4
4.05.0-13.5
fixed
suse enterprise sap 15 SP5
4.05.0-13.5
fixed
suse enterprise sap 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise sap 15 SP7
4.14.2-150600.1.2
fixed
suse enterprise server 15
4.05.0-4.25
fixed
suse enterprise server 15 SP1
4.05.0-4.25
fixed
suse enterprise server 15 SP2
4.05.0-13.5
fixed
suse enterprise server 15 SP3
4.05.0-13.5
fixed
suse enterprise server 15 SP4
4.05.0-13.5
fixed
suse enterprise server 15 SP5
4.05.0-13.5
fixed
suse enterprise server 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise server 15 SP7
4.14.2-150600.1.2
fixed
ocaml-compiler-libs
suse enterprise desktop 15
4.05.0-4.25
fixed
suse enterprise desktop 15 SP1
4.05.0-4.25
fixed
suse enterprise desktop 15 SP2
4.05.0-13.5
fixed
suse enterprise desktop 15 SP3
4.05.0-13.5
fixed
suse enterprise desktop 15 SP4
4.05.0-13.5
fixed
suse enterprise desktop 15 SP5
4.05.0-13.5
fixed
suse enterprise desktop 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise desktop 15 SP7
4.14.2-150600.1.2
fixed
suse enterprise sap 15
4.05.0-4.25
fixed
suse enterprise sap 15 SP1
4.05.0-4.25
fixed
suse enterprise sap 15 SP2
4.05.0-13.5
fixed
suse enterprise sap 15 SP3
4.05.0-13.5
fixed
suse enterprise sap 15 SP4
4.05.0-13.5
fixed
suse enterprise sap 15 SP5
4.05.0-13.5
fixed
suse enterprise sap 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise sap 15 SP7
4.14.2-150600.1.2
fixed
suse enterprise server 15
4.05.0-4.25
fixed
suse enterprise server 15 SP1
4.05.0-4.25
fixed
suse enterprise server 15 SP2
4.05.0-13.5
fixed
suse enterprise server 15 SP3
4.05.0-13.5
fixed
suse enterprise server 15 SP4
4.05.0-13.5
fixed
suse enterprise server 15 SP5
4.05.0-13.5
fixed
suse enterprise server 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise server 15 SP7
4.14.2-150600.1.2
fixed
ocaml-compiler-libs-devel
suse enterprise desktop 15
4.05.0-4.25
fixed
suse enterprise desktop 15 SP1
4.05.0-4.25
fixed
suse enterprise desktop 15 SP2
4.05.0-13.5
fixed
suse enterprise desktop 15 SP3
4.05.0-13.5
fixed
suse enterprise desktop 15 SP4
4.05.0-13.5
fixed
suse enterprise desktop 15 SP5
4.05.0-13.5
fixed
suse enterprise desktop 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise desktop 15 SP7
4.14.2-150600.1.2
fixed
suse enterprise sap 15
4.05.0-4.25
fixed
suse enterprise sap 15 SP1
4.05.0-4.25
fixed
suse enterprise sap 15 SP2
4.05.0-13.5
fixed
suse enterprise sap 15 SP3
4.05.0-13.5
fixed
suse enterprise sap 15 SP4
4.05.0-13.5
fixed
suse enterprise sap 15 SP5
4.05.0-13.5
fixed
suse enterprise sap 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise sap 15 SP7
4.14.2-150600.1.2
fixed
suse enterprise server 15
4.05.0-4.25
fixed
suse enterprise server 15 SP1
4.05.0-4.25
fixed
suse enterprise server 15 SP2
4.05.0-13.5
fixed
suse enterprise server 15 SP3
4.05.0-13.5
fixed
suse enterprise server 15 SP4
4.05.0-13.5
fixed
suse enterprise server 15 SP5
4.05.0-13.5
fixed
suse enterprise server 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise server 15 SP7
4.14.2-150600.1.2
fixed
ocaml-ocamldoc
suse enterprise desktop 15 SP1
4.05.0-4.25
fixed
suse enterprise desktop 15 SP2
4.05.0-13.5
fixed
suse enterprise desktop 15 SP3
4.05.0-13.5
fixed
suse enterprise desktop 15 SP4
4.05.0-13.5
fixed
suse enterprise desktop 15 SP5
4.05.0-13.5
fixed
suse enterprise desktop 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise desktop 15 SP7
4.14.2-150600.1.2
fixed
suse enterprise sap 15 SP1
4.05.0-4.25
fixed
suse enterprise sap 15 SP2
4.05.0-13.5
fixed
suse enterprise sap 15 SP3
4.05.0-13.5
fixed
suse enterprise sap 15 SP4
4.05.0-13.5
fixed
suse enterprise sap 15 SP5
4.05.0-13.5
fixed
suse enterprise sap 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise sap 15 SP7
4.14.2-150600.1.2
fixed
suse enterprise server 15 SP1
4.05.0-4.25
fixed
suse enterprise server 15 SP2
4.05.0-13.5
fixed
suse enterprise server 15 SP3
4.05.0-13.5
fixed
suse enterprise server 15 SP4
4.05.0-13.5
fixed
suse enterprise server 15 SP5
4.05.0-13.5
fixed
suse enterprise server 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise server 15 SP7
4.14.2-150600.1.2
fixed
ocaml-rpm-macros
suse enterprise desktop 15
4.05.0-4.25
fixed
suse enterprise desktop 15 SP1
4.05.0-4.25
fixed
suse enterprise sap 15
4.05.0-4.25
fixed
suse enterprise sap 15 SP1
4.05.0-4.25
fixed
suse enterprise server 15
4.05.0-4.25
fixed
suse enterprise server 15 SP1
4.05.0-4.25
fixed
ocaml-runtime
suse enterprise desktop 15
4.05.0-4.25
fixed
suse enterprise desktop 15 SP1
4.05.0-4.25
fixed
suse enterprise desktop 15 SP2
4.05.0-13.5
fixed
suse enterprise desktop 15 SP3
4.05.0-13.5
fixed
suse enterprise desktop 15 SP4
4.05.0-13.5
fixed
suse enterprise desktop 15 SP5
4.05.0-13.5
fixed
suse enterprise desktop 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise desktop 15 SP7
4.14.2-150600.1.2
fixed
suse enterprise sap 15
4.05.0-4.25
fixed
suse enterprise sap 15 SP1
4.05.0-4.25
fixed
suse enterprise sap 15 SP2
4.05.0-13.5
fixed
suse enterprise sap 15 SP3
4.05.0-13.5
fixed
suse enterprise sap 15 SP4
4.05.0-13.5
fixed
suse enterprise sap 15 SP5
4.05.0-13.5
fixed
suse enterprise sap 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise sap 15 SP7
4.14.2-150600.1.2
fixed
suse enterprise server 15
4.05.0-4.25
fixed
suse enterprise server 15 SP1
4.05.0-4.25
fixed
suse enterprise server 15 SP2
4.05.0-13.5
fixed
suse enterprise server 15 SP3
4.05.0-13.5
fixed
suse enterprise server 15 SP4
4.05.0-13.5
fixed
suse enterprise server 15 SP5
4.05.0-13.5
fixed
suse enterprise server 15 SP6
4.14.2-150600.1.2
fixed
suse enterprise server 15 SP7
4.14.2-150600.1.2
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libguestfs
RHEL 6
1:1.20.11-20.el6
fixed
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-bash-completion
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-devel
RHEL 6
1:1.20.11-20.el6
fixed
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-gfs2
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-gobject
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-gobject-devel
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-gobject-doc
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-inspect-icons
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-java
RHEL 6
1:1.20.11-20.el6
fixed
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-java-devel
RHEL 6
1:1.20.11-20.el6
fixed
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-javadoc
RHEL 6
1:1.20.11-20.el6
fixed
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-man-pages-ja
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-man-pages-uk
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-rescue
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-rsync
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-tools
RHEL 6
1:1.20.11-20.el6
fixed
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-tools-c
RHEL 6
1:1.20.11-20.el6
fixed
RHEL 7
1:1.32.7-3.el7
fixed
libguestfs-xfs
RHEL 7
1:1.32.7-3.el7
fixed
lua-guestfs
RHEL 7
1:1.32.7-3.el7
fixed
ocaml
RHEL 6
0:3.11.2-5.el6
fixed
RHEL 7
0:4.01.0-22.7.el7_2
fixed
ocaml-camlp4
RHEL 6
0:3.11.2-5.el6
fixed
RHEL 7
0:4.01.0-22.7.el7_2
fixed
ocaml-camlp4-devel
RHEL 6
0:3.11.2-5.el6
fixed
RHEL 7
0:4.01.0-22.7.el7_2
fixed
ocaml-compiler-libs
RHEL 7
0:4.01.0-22.7.el7_2
fixed
ocaml-docs
RHEL 6
0:3.11.2-5.el6
fixed
RHEL 7
0:4.01.0-22.7.el7_2
fixed
ocaml-emacs
RHEL 6
0:3.11.2-5.el6
fixed
RHEL 7
0:4.01.0-22.7.el7_2
fixed
ocaml-labltk
RHEL 6
0:3.11.2-5.el6
fixed
RHEL 7
0:4.01.0-22.7.el7_2
fixed
ocaml-labltk-devel
RHEL 6
0:3.11.2-5.el6
fixed
RHEL 7
0:4.01.0-22.7.el7_2
fixed
ocaml-libguestfs
RHEL 6
1:1.20.11-20.el6
fixed
RHEL 7
1:1.32.7-3.el7
fixed
ocaml-libguestfs-devel
RHEL 6
1:1.20.11-20.el6
fixed
RHEL 7
1:1.32.7-3.el7
fixed
ocaml-ocamldoc
RHEL 6
0:3.11.2-5.el6
fixed
RHEL 7
0:4.01.0-22.7.el7_2
fixed
ocaml-runtime
RHEL 6
0:3.11.2-5.el6
fixed
RHEL 7
0:4.01.0-22.7.el7_2
fixed
ocaml-source
RHEL 6
0:3.11.2-5.el6
fixed
RHEL 7
0:4.01.0-22.7.el7_2
fixed
ocaml-x11
RHEL 6
0:3.11.2-5.el6
fixed
RHEL 7
0:4.01.0-22.7.el7_2
fixed
perl-Sys-Guestfs
RHEL 6
1:1.20.11-20.el6
fixed
RHEL 7
1:1.32.7-3.el7
fixed
python-libguestfs
RHEL 6
1:1.20.11-20.el6
fixed
RHEL 7
1:1.32.7-3.el7
fixed
ruby-libguestfs
RHEL 6
1:1.20.11-20.el6
fixed
RHEL 7
1:1.32.7-3.el7
fixed
virt-dib
RHEL 7
1:1.32.7-3.el7
fixed
virt-p2v
RHEL 7
0:1.32.7-2.el7
fixed
virt-v2v
RHEL 7
1:1.32.7-3.el7
fixed
References