CVE-2002-2017: Critical severity SAS Base vulnerability
Published Dec 31, 2002
·Updated
sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.
Affected Software
2 affected components
SAS Base=8.0
SAS Integration Technologies=8.0
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Jul 14, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2017?
CVE-2002-2017 is considered to be a high severity vulnerability due to the potential for local users to execute arbitrary code.
2
How do I fix CVE-2002-2017?
To fix CVE-2002-2017, ensure that the authprog environment variable is not set to reference untrusted programs.
3
Who is affected by CVE-2002-2017?
CVE-2002-2017 affects users of SAS/Base 8.0 and SAS Integration Technologies 8.0.
4
What type of attack does CVE-2002-2017 vector facilitate?
CVE-2002-2017 facilitates local code execution attacks by allowing manipulation of environment variables.
5
Can CVE-2002-2017 be exploited remotely?
CVE-2002-2017 requires local access, thus it cannot be exploited remotely.