OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.
| Software | From | Fixed in |
|---|---|---|
| fedoraproject / fedora | 24 | 24.x |
| opensuse / opensuse | 13.2 | 13.2.x |
| ocaml / ocaml | - | 4.02.3.x |