OCaml 3.12.1 and earlier computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
{ "binaries": [ { "binary_name": "camlp4", "binary_version": "4.01.0-3ubuntu3" }, { "binary_name": "camlp4-extra", "binary_version": "4.01.0-3ubuntu3" }, { "binary_name": "ocaml", "binary_version": "4.01.0-3ubuntu3" }, { "binary_name": "ocaml-base", "binary_version": "4.01.0-3ubuntu3" }, { "binary_name": "ocaml-base-nox", "binary_version": "4.01.0-3ubuntu3" }, { "binary_name": "ocaml-compiler-libs", "binary_version": "4.01.0-3ubuntu3" }, { "binary_name": "ocaml-interp", "binary_version": "4.01.0-3ubuntu3" }, { "binary_name": "ocaml-mode", "binary_version": "4.01.0-3ubuntu3" }, { "binary_name": "ocaml-native-compilers", "binary_version": "4.01.0-3ubuntu3" }, { "binary_name": "ocaml-nox", "binary_version": "4.01.0-3ubuntu3" }, { "binary_name": "ocaml-source", "binary_version": "4.01.0-3ubuntu3" } ], "availability": "No subscription required", "ubuntu_priority": "low" }