PT-2002-2738 · Sas · Sas/Base

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-2017

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAS/Base version 8.0
Description The issue allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program. This malicious program is then executed, posing a significant risk.
Recommendations For SAS/Base version 8.0, consider restricting the ability to set the authprog environment variable to prevent malicious program execution until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-2017

Produtos afetados

Sas/Base