CVE Vulnerabilities

CVE-2002-0218

Published: May 16, 2002 | Modified: Sep 11, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a command line argument.

Affected Software

Name Vendor Start Version End Version
Sas_base Sas 8.0 (including) 8.0 (including)
Sas_base Sas 8.1 (including) 8.1 (including)
Sas_integration_technologies Sas 8.0 (including) 8.0 (including)
Sas_integration_technologies Sas 8.1 (including) 8.1 (including)

References