CVE-2017-9772: Ocaml
Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.
Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variable.
Affected products
- Ocaml Ocaml: version 4.04.0 only; version 4.04.1 only
Published 2017-06-23. Last modified 2026-06-17.