SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 68807: The TABULATE procedure has a stack-corruption vulnerability that is related to the use of a long string for the ALL keyword

DetailsHotfixAboutRate It

Severity: Medium

Description: A long string for the ALL keyword in PROC TABULATE causes a stack corruption, and SAS can crash.

Potential Impact: Stack corruption can potentially lead to denial of service (DoS) or arbitrary code execution.

Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemBase SASMicrosoft® Windows® for x64V.03.00V.03.00ViyaViya
Microsoft Windows 8 Enterprise 32-bitV.03.00Viya
Microsoft Windows 8 Enterprise x64V.03.00V.03.00ViyaViya
Microsoft Windows 8 Pro 32-bitV.03.00Viya
Microsoft Windows 8 Pro x64V.03.00V.03.00ViyaViya
Microsoft Windows 8.1 Enterprise 32-bitV.03.00Viya
Microsoft Windows 8.1 Enterprise x64V.03.00V.03.00ViyaViya
Microsoft Windows 8.1 Pro 32-bitV.03.00Viya
Microsoft Windows 8.1 Pro x64V.03.00V.03.00ViyaViya
Microsoft Windows 10V.03.00V.03.00ViyaViya
Microsoft Windows 11V.03.00Viya
Microsoft Windows 95/98V.03.00Viya
Microsoft Windows 2000 Advanced ServerV.03.00Viya
Microsoft Windows 2000 Datacenter ServerV.03.00Viya
Microsoft Windows 2000 ServerV.03.00Viya
Microsoft Windows 2000 ProfessionalV.03.00Viya
Microsoft Windows NT WorkstationV.03.00Viya
Microsoft Windows Server 2003 Datacenter EditionV.03.00Viya
Microsoft Windows Server 2003 Enterprise EditionV.03.00Viya
Microsoft Windows Server 2003 Standard EditionV.03.00Viya
Microsoft Windows Server 2003 for x64V.03.00V.03.00ViyaViya
Microsoft Windows Server 2008V.03.00Viya
Microsoft Windows Server 2008 R2V.03.00V.03.00ViyaViya
Microsoft Windows Server 2008 for x64V.03.00V.03.00ViyaViya
Microsoft Windows Server 2012 DatacenterV.03.00V.03.00ViyaViya
Microsoft Windows Server 2012 R2 DatacenterV.03.00V.03.00ViyaViya
Microsoft Windows Server 2012 R2 StdV.03.00V.03.00ViyaViya
Microsoft Windows Server 2012 StdV.03.00V.03.00ViyaViya
Microsoft Windows Server 2016V.03.00V.03.00ViyaViya
Microsoft Windows Server 2019V.03.00V.03.00ViyaViya
Microsoft Windows Server 2022V.03.00Viya
Microsoft Windows XP ProfessionalV.03.00Viya
Windows 7 Enterprise 32 bitV.03.00Viya
Windows 7 Enterprise x64V.03.00V.03.00ViyaViya
Windows 7 Home Premium 32 bitV.03.00Viya
Windows 7 Home Premium x64V.03.00V.03.00ViyaViya
Windows 7 Professional 32 bitV.03.00Viya
Windows 7 Professional x64V.03.00V.03.00ViyaViya
Windows 7 Ultimate 32 bitV.03.00Viya
Windows 7 Ultimate x64V.03.00V.03.00ViyaViya
Windows Millennium Edition (Me)V.03.00Viya
Windows VistaV.03.00Viya
Windows Vista for x64V.03.00V.03.00ViyaViya
Linux for x64V.03.00V.03.00ViyaViya
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.