SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 69658: The RAND function contains a security vulnerability

DetailsHotfixAboutRate It

Severity: High

Description: If the distribution argument to the RAND Function is very long, SAS might issue a segmentation violation and stop processing, become unresponsive, or terminate.

Potential Impact: The resulting segmentation violation introduces a potential security risk.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemBase SASz/OS9.4_M59.4_M89.4 TS1M59.4 TS1M8
z/OS 64-bit9.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft® Windows® for x649.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows 8 Enterprise 32-bit9.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows 8 Enterprise x649.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows 8 Pro 32-bit9.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows 8 Pro x649.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows 8.1 Enterprise 32-bit9.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows 8.1 Enterprise x649.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows 8.1 Pro 32-bit9.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows 8.1 Pro x649.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows 109.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows Server 20089.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows Server 2008 R29.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows Server 2012 Datacenter9.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows Server 2008 for x649.4_M59.4_M89.4 TS1M59.4 TS1M8
Solaris for x649.4_M59.4_M89.4 TS1M59.4 TS1M8
HP-UX IPF9.4_M59.4_M89.4 TS1M59.4 TS1M8
Linux for x649.4_M59.4_M89.4 TS1M59.4 TS1M8
64-bit Enabled Solaris9.4_M59.4_M89.4 TS1M59.4 TS1M8
64-bit Enabled AIX9.4_M59.4_M89.4 TS1M59.4 TS1M8
Windows 7 Ultimate x649.4_M59.4_M89.4 TS1M59.4 TS1M8
Windows 7 Ultimate 32 bit9.4_M59.4_M89.4 TS1M59.4 TS1M8
Windows 7 Professional x649.4_M59.4_M89.4 TS1M59.4 TS1M8
Windows 7 Professional 32 bit9.4_M59.4_M89.4 TS1M59.4 TS1M8
Windows 7 Home Premium x649.4_M59.4_M89.4 TS1M59.4 TS1M8
Windows 7 Home Premium 32 bit9.4_M59.4_M89.4 TS1M59.4 TS1M8
Windows 7 Enterprise x649.4_M59.4_M89.4 TS1M59.4 TS1M8
Windows 7 Enterprise 32 bit9.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows Server 20169.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows Server 2012 Std9.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows Server 2012 R2 Std9.4_M59.4_M89.4 TS1M59.4 TS1M8
Microsoft Windows Server 2012 R2 Datacenter9.4_M59.4_M89.4 TS1M59.4 TS1M8
SAS SystemSAS Visual Analytics (on SAS Viya)Cloud Foundry8.1Stable 2022.11ViyaViya
Linux for x648.1Stable 2022.11ViyaViya
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.