Vulnerability Description
sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sas | Base | 8.0 |
| Sas | Integration Technologies | 8.0 |
References
- http://online.securityfocus.com/archive/1/253183
- http://www.iss.net/security_center/static/8024.php
- http://www.securityfocus.com/bid/3994
- http://online.securityfocus.com/archive/1/253183
- http://www.iss.net/security_center/static/8024.php
- http://www.securityfocus.com/bid/3994
FAQ
What is CVE-2002-2017?
CVE-2002-2017 is a vulnerability with a CVSS score of 10.0 (HIGH). sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.
How severe is CVE-2002-2017?
CVE-2002-2017 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-2017?
Check the references section above for vendor advisories and patch information. Affected products include: Sas Base, Sas Integration Technologies.