SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 66317: Various CAS functions can create a stack-corruption vulnerability

DetailsHotfixAboutRate It

Severity: Medium

Description: User functions (CDF, SDF, PDF, QUANTILE, SQUANTILE, FINANCE) or their counterparts in the FCMP procedure can result in access-violation errors or SAS® software crashes.

Potential Impact: Under certain circumstances, a stack corruption occurs. This corruption can result in a vulnerability to arbitrary code execution or to denial-of-service attacks.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemBase SASz/OS9.4_M69.4_M79.4 TS1M69.4 TS1M7
z/OS 64-bit9.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft® Windows® for x649.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows 8 Enterprise 32-bit9.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows 8 Enterprise x649.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows 8 Pro 32-bit9.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows 8 Pro x649.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows 8.1 Enterprise 32-bit9.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows 8.1 Enterprise x649.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows 8.1 Pro 32-bit9.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows 8.1 Pro x649.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows 109.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows Server 2012 Datacenter9.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows Server 2012 R2 Datacenter9.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows Server 2012 R2 Std9.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows Server 2012 Std9.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows Server 20169.4_M69.4_M79.4 TS1M69.4 TS1M7
Microsoft Windows Server 20199.4_M69.4_M79.4 TS1M69.4 TS1M7
Windows 7 Enterprise 32 bit9.4_M69.4_M79.4 TS1M69.4 TS1M7
Windows 7 Enterprise x649.4_M69.4_M79.4 TS1M69.4 TS1M7
Windows 7 Home Premium 32 bit9.4_M69.4_M79.4 TS1M69.4 TS1M7
Windows 7 Home Premium x649.4_M69.4_M79.4 TS1M69.4 TS1M7
Windows 7 Professional 32 bit9.4_M69.4_M79.4 TS1M69.4 TS1M7
Windows 7 Professional x649.4_M69.4_M79.4 TS1M69.4 TS1M7
Windows 7 Ultimate 32 bit9.4_M69.4_M79.4 TS1M69.4 TS1M7
Windows 7 Ultimate x649.4_M69.4_M79.4 TS1M69.4 TS1M7
64-bit Enabled AIX9.4_M69.4_M79.4 TS1M69.4 TS1M7
64-bit Enabled Solaris9.4_M69.4_M79.4 TS1M69.4 TS1M7
HP-UX IPF9.4_M69.4_M79.4 TS1M69.4 TS1M7
Linux for x649.4_M69.4_M79.4 TS1M69.4 TS1M7
Solaris for x649.4_M69.4_M79.4 TS1M69.4 TS1M7
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.