SUPPORT / SAMPLES & SAS NOTES
 

Support

Installation Note 37746: Security vulnerability with sasperm binary in SAS® 9.1.3 SP4 and SAS® 9.2

DetailsHotfixAboutRate It

If certain conditions are met, it is possible for a user to escalate privileges to that of the root user by running the sasperm binary in the !SASROOT/utilities/bin directory.



Operating System and Release Information

Product FamilyProductSystemSAS Release
ReportedFixed*
SAS SystemSAS/SHARE64-bit Enabled AIX9.1 TS1M3 SP49.2 TS2M0
64-bit Enabled HP-UX9.1 TS1M3 SP49.2 TS2M0
64-bit Enabled Solaris9.1 TS1M3 SP49.2 TS2M0
HP-UX IPF9.1 TS1M3 SP49.2 TS2M0
Linux9.1 TS1M3 SP49.2 TS2M0
Linux on Itanium9.1 TS1M3 SP49.2 TS2M0
Solaris for x649.1 TS1M3 SP49.2 TS2M0
Tru64 UNIX9.1 TS1M3 SP49.2 TS2M0
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.