First published: Tue Dec 31 2002(Updated: )
sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAS Base | =8.0 | |
SAS Integration Technologies | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2017 is considered to be a high severity vulnerability due to the potential for local users to execute arbitrary code.
To fix CVE-2002-2017, ensure that the authprog environment variable is not set to reference untrusted programs.
CVE-2002-2017 affects users of SAS/Base 8.0 and SAS Integration Technologies 8.0.
CVE-2002-2017 facilitates local code execution attacks by allowing manipulation of environment variables.
CVE-2002-2017 requires local access, thus it cannot be exploited remotely.