CVE-2002-0219: Buffer Overflow
Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via large command line argument.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0219?
CVE-2002-0219 is considered a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2002-0219?
To fix CVE-2002-0219, users should upgrade to a patched version of SAS/Base or SAS/Integration Technologies beyond versions 8.1.
Who is affected by CVE-2002-0219?
Local users running SAS/Base versions 8.0 or 8.1 and SAS/Integration Technologies versions 8.0 or 8.1 are affected by CVE-2002-0219.
What types of attacks can CVE-2002-0219 facilitate?
CVE-2002-0219 can facilitate local user attacks that exploit buffer overflow vulnerabilities to execute arbitrary code.
Is CVE-2002-0219 still relevant today?
While CVE-2002-0219 was reported in 2002, it remains relevant for organizations still using the affected SAS software versions.