Vulnerability Description
sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sas | Base | 8.0 |
| Sas | Integration Technologies | 8.0 |
References
- http://online.securityfocus.com/archive/1/253183
- http://securitytracker.com/id?1003406
- http://www.sas.com/service/techsup/unotes/SN/004/004201.htmlPatch
- http://www.securityfocus.com/bid/3995
- http://online.securityfocus.com/archive/1/253183
- http://securitytracker.com/id?1003406
- http://www.sas.com/service/techsup/unotes/SN/004/004201.htmlPatch
- http://www.securityfocus.com/bid/3995
FAQ
What is CVE-2002-2018?
CVE-2002-2018 is a vulnerability with a CVSS score of 7.2 (HIGH). sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault.
How severe is CVE-2002-2018?
CVE-2002-2018 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-2018?
Check the references section above for vendor advisories and patch information. Affected products include: Sas Base, Sas Integration Technologies.