First published: Fri May 03 2002(Updated: )
Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a command line argument.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAS Base | =8.0 | |
SAS Base | =8.1 | |
SAS Integration Technologies | =8.0 | |
SAS Integration Technologies | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0218 has a high severity level due to the potential for local users to execute arbitrary code.
To fix CVE-2002-0218, update SAS/Base and SAS/Integration Technologies to versions 8.2 or later.
CVE-2002-0218 affects local users of SAS/Base versions 8.0 and 8.1, and SAS/Integration Technologies versions 8.0 and 8.1.
Vulnerable systems include those running SAS/Base 8.0 or 8.1, and SAS/Integration Technologies 8.0 or 8.1.
CVE-2002-0218 was reported in 2002.