The camlbadeserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "low", "binaries": [ { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "camlp4" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "camlp4-dbgsym" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "camlp4-extra" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "camlp4-extra-dbgsym" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "ocaml" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "ocaml-base" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "ocaml-base-dbgsym" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "ocaml-base-nox" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "ocaml-base-nox-dbgsym" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "ocaml-compiler-libs" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "ocaml-interp" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "ocaml-mode" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "ocaml-native-compilers" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "ocaml-native-compilers-dbgsym" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "ocaml-nox" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "ocaml-nox-dbgsym" }, { "binary_version": "4.01.0-3ubuntu3.1+esm1", "binary_name": "ocaml-source" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "low", "binaries": [ { "binary_version": "4.02.3-5ubuntu2+esm1", "binary_name": "ocaml" }, { "binary_version": "4.02.3-5ubuntu2+esm1", "binary_name": "ocaml-base" }, { "binary_version": "4.02.3-5ubuntu2+esm1", "binary_name": "ocaml-base-dbgsym" }, { "binary_version": "4.02.3-5ubuntu2+esm1", "binary_name": "ocaml-base-nox" }, { "binary_version": "4.02.3-5ubuntu2+esm1", "binary_name": "ocaml-base-nox-dbgsym" }, { "binary_version": "4.02.3-5ubuntu2+esm1", "binary_name": "ocaml-compiler-libs" }, { "binary_version": "4.02.3-5ubuntu2+esm1", "binary_name": "ocaml-interp" }, { "binary_version": "4.02.3-5ubuntu2+esm1", "binary_name": "ocaml-mode" }, { "binary_version": "4.02.3-5ubuntu2+esm1", "binary_name": "ocaml-native-compilers" }, { "binary_version": "4.02.3-5ubuntu2+esm1", "binary_name": "ocaml-native-compilers-dbgsym" }, { "binary_version": "4.02.3-5ubuntu2+esm1", "binary_name": "ocaml-nox" }, { "binary_version": "4.02.3-5ubuntu2+esm1", "binary_name": "ocaml-nox-dbgsym" }, { "binary_version": "4.02.3-5ubuntu2+esm1", "binary_name": "ocaml-source" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "low", "binaries": [ { "binary_version": "4.05.0-10ubuntu1+esm1", "binary_name": "ocaml" }, { "binary_version": "4.05.0-10ubuntu1+esm1", "binary_name": "ocaml-base" }, { "binary_version": "4.05.0-10ubuntu1+esm1", "binary_name": "ocaml-base-dbgsym" }, { "binary_version": "4.05.0-10ubuntu1+esm1", "binary_name": "ocaml-base-nox" }, { "binary_version": "4.05.0-10ubuntu1+esm1", "binary_name": "ocaml-base-nox-dbgsym" }, { "binary_version": "4.05.0-10ubuntu1+esm1", "binary_name": "ocaml-compiler-libs" }, { "binary_version": "4.05.0-10ubuntu1+esm1", "binary_name": "ocaml-interp" }, { "binary_version": "4.05.0-10ubuntu1+esm1", "binary_name": "ocaml-mode" }, { "binary_version": "4.05.0-10ubuntu1+esm1", "binary_name": "ocaml-nox" }, { "binary_version": "4.05.0-10ubuntu1+esm1", "binary_name": "ocaml-nox-dbgsym" }, { "binary_version": "4.05.0-10ubuntu1+esm1", "binary_name": "ocaml-source" } ] }