CVE-2002-0218: High severity SAS Sas Base vulnerability
Published May 3, 2002
·Updated
Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a command line argument.
Affected Software
4 affected components
SAS Sas Base=8.1
SAS Sas Integration Technologies=8.1
SAS Sas Base=8.0
SAS Sas Integration Technologies=8.0
Remediation
Patch Available
Patch Available
Event History
May 3, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0218?
CVE-2002-0218 has a high severity level due to the potential for local users to execute arbitrary code.
2
How do I fix CVE-2002-0218?
To fix CVE-2002-0218, update SAS/Base and SAS/Integration Technologies to versions 8.2 or later.
3
Who is affected by CVE-2002-0218?
CVE-2002-0218 affects local users of SAS/Base versions 8.0 and 8.1, and SAS/Integration Technologies versions 8.0 and 8.1.
4
What systems are vulnerable to CVE-2002-0218?
Vulnerable systems include those running SAS/Base 8.0 or 8.1, and SAS/Integration Technologies 8.0 or 8.1.
5
When was CVE-2002-0218 reported?
CVE-2002-0218 was reported in 2002.