CVE-2015-8869: Fedoraproject Fedora
Critical severity, CVSS 9.1. EPSS: 5.3% chance of exploitation in the next 30 days.
OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.
Affected products
- Fedoraproject Fedora: version 24 only
- Ocaml Ocaml: up to and including 4.02.3
- Opensuse Opensuse: version 13.2 only
Published 2016-06-13. Last modified 2026-06-17.